CVE-2026-23919
CVE-2026-23919 is a medium-severity vulnerability in Zabbix with a CVSS 3.x base score of 6.0. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-488.
Key facts
- Severity: Medium (CVSS 3.x base score 6.0)
- CVSS v4: 7.1
- EPSS exploit prediction: 0% (14th percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2026-14950
- Weakness: CWE-488
- Affected product: Zabbix
- Published:
- Last modified:
Description
For performance reasons Zabbix Server/Proxy reuses JavaScript (Duktape) contexts (used in script items, JavaScript reprocessing, Webhooks). This can lead to confidentiality loss where a regular (non-super) Zabbix administrator leaks data for hosts they do not have access to. A fix has been released that makes the built in Zabbix JavaScript objects read-only, but please be advised that usage of global JavaScript variables is not recommended because their content could be leaked. More information <a href='https://www.zabbix.com/documentation/7.4/en/manual/installation/known_issues#preprocessing-global-variables-are-unsafe'>in Zabbix documentation</a>.
Frequently asked questions
- What is CVE-2026-23919?
- For performance reasons Zabbix Server/Proxy reuses JavaScript (Duktape) contexts (used in script items, JavaScript reprocessing, Webhooks). This can lead to confidentiality loss where a regular (non-super) Zabbix administrator leaks data for hosts they do not have access to. A fix has been released that makes the built in Zabbix JavaScript objects read-only, but please be advised that usage of global JavaScript variables is not recommended because their content could be leaked. More information <a href='https://www.zabbix.com/documentation/7.4/en/manual/installation/known_issues#preprocessing-global-variables-are-unsafe'>in Zabbix documentation</a>.
- How severe is CVE-2026-23919?
- CVE-2026-23919 has a CVSS 3.x base score of 6.0, rated medium severity. It is exploitable over network with low attack complexity, requires high privileges and no user interaction. Impact on confidentiality is high, integrity low, and availability low.
- Is CVE-2026-23919 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (14th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-23919?
- CVE-2026-23919 affects Zabbix. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-23919?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- Does CVE-2026-23919 have an EU (EUVD) identifier?
- Yes. CVE-2026-23919 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2026-14950.
- When was CVE-2026-23919 published?
- CVE-2026-23919 was published on 2026-03-24 and last updated on 2026-09-18.
References
Affected products (1)
- cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:*
More vulnerabilities in Zabbix
- CVE-2007-0640 — Critical (CVSS 10.0): Buffer overflow in ZABBIX before 1.1.5 has unknown impact and attack vectors related to "SNMP IP addresses."
- CVE-2024-42327 — Critical (CVSS 9.9): A non-admin user account on the Zabbix frontend with the default User role, or with any other role that gives API…
- CVE-2024-22116 — Critical (CVSS 9.9): An administrator with restricted permissions can exploit the script execution functionality within the Monitoring Hosts…
- CVE-2020-11800 — Critical (CVSS 9.8): Zabbix Server 2.2.x and 3.0.x before 3.0.31, and 3.2 allows remote attackers to execute arbitrary code.
- CVE-2013-3738 — Critical (CVSS 9.8): A File Inclusion vulnerability exists in Zabbix 2.0.6 due to inadequate sanitization of request strings in CGI scripts,…
- CVE-2013-5743 — Critical (CVSS 9.8): Multiple SQL injection vulnerabilities in Zabbix 1.8.x before 1.8.18rc1, 2.0.x before 2.0.9rc1, and 2.1.x before 2.1.7.
Other CWE-488 vulnerabilities
- CVE-2026-16326 — Critical (CVSS 10.0): In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in stateless mode, which may…
- CVE-2026-16498 — Critical (CVSS 10.0): The terraform-mcp-server before version 1.1.0 is vulnerable to a cross-tenant credential reuse issue in the…
- CVE-2026-19931 — Critical (CVSS 9.8): A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication,…
- CVE-2025-47928 — Critical (CVSS 9.1): Spotipy is a Python library for the Spotify Web API. As of commit 4f5759dbfb4506c7b6280572a4db1aabc1ac778d, using…
- CVE-2024-27455 — Critical (CVSS 9.1): In the Bentley ALIM Web application, certain configuration settings can cause exposure of a user's ALIM session token…
- CVE-2026-86492 — High (CVSS 8.5): In JetBrains YouTrack before 2026.2.18634 a shared token cache allowed cross-tenant theft of GitHub App installation…