CVE-2026-23919Disclosure(zabbix / zabbix)

LOWCVSS 6.0 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

For performance reasons Zabbix Server/Proxy reuses JavaScript (Duktape) contexts (used in script items, JavaScript reprocessing, Webhooks). This can lead to confidentiality loss where a regular (non-super) Zabbix administrator leaks data for hosts they do not have access to. A fix has been released that makes the built in Zabbix JavaScript objects read-only, but please be advised that usage of global JavaScript variables is not recommended because their content could be leaked. More information <a href='https://www.zabbix.com/documentation/7.4/en/manual/installation/known_issues#preprocessing-global-variables-are-unsafe'>in Zabbix documentation</a>.

0.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-488

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • zabbix

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-03-27); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
zabbix

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-27: 1Mentions · 2026-03-30: 1Technical Details · 2026-03-27: 103-2703-30
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidades en productos Zabbix ❗ CVE-2026-23921 ❗ CVE-2026-23920 ❗ CVE-2026-23919 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-zabbix/ https://t.co/qiJNKLih5o

    Post summary

    The post announces several CVE vulnerabilities in Zabbix products and links to additional information, but lacks technical details, exploitation evidence, or patch guidance.

    10020179
    6.6K followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    [ZBX-27638] Insufficient isolation of JavaScript (Duktape) execution context on Zabbix Server (CVE-2026-23919) - ZABBIX SUPPORT https://support.zabbix.com/browse/ZBX-27638

    Post summary

    Zabbix’s support page announces an insufficient isolation flaw in its JavaScript execution environment (CVE‑2026‑23919) but provides no PoC, exploit, patch, or active exploitation details.

    00001433
    6.8K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appzabbixzabbix---

Explore more