CVE-2026-23926Disclosure(zabbix / zabbix)

LOWCVSS 6.8 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch zabbix zabbix systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An authenticated (non-super) administrator can create a maintenance period with a JavaScript payload that is executed by any user that opens tooltip for that maintenance period in the Host navigator widget. This can allow the attacker to perform unauthorized actions depending on which user opens the tooltip.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • zabbix

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-05-11); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
zabbix

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-05-06: 1Mentions · 2026-05-08: 1Mentions · 2026-05-11: 2Mentions · 2026-05-31: 1Patch / Workaround · 2026-05-08: 1Technical Details · 2026-05-06: 1Technical Details · 2026-05-08: 105-0605-0805-1105-31
Signal classification3 categories
Disclosure
240.0%
General
240.0%
Patch
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-061
Disclosure1
2026-05-081
Patch1
2026-05-112
General2
2026-05-311
Disclosure1
Full discourse5 posts
  • Gray Hats@the_yellow_fall
    Patch

    Zabbix fixes high-severity XSS (CVE-2026-23926) and Oracle injection flaws. Don't let your monitoring tool become a backdoor—upgrade your Zabbix server now! #Zabbix #CyberSecurity #InfoSec #XSS #Oracle #Monitoring #PatchAlert #TechSecurity https://securityonline.info/zabbix-security-patches-xss-oracle-injection-cve-2026-23926/ https://t.co/txtPaWZyYs

    Post summary

    The post announces a patch for a high‑severity XSS and Oracle injection flaw (CVE‑2026‑23926) in Zabbix, urging users to upgrade.

    01072414
    12.5K followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Zabbix ❗ CVE-2026-23928 ❗ CVE-2026-23926 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-zabbix-2/ https://t.co/hmJvPi9Vw7

    Post summary

    The post announces two Zabbix CVEs and provides links for more information, without detailing exploitation or mitigation.

    00021137
    6.7K followersView on X
  • 【公式】SCSK Zabbix@SCSK_Zabbix
    Disclosure

    ★ 【緊急】26年5月公開のZabbix の脆弱性情報 ★ 弊社ブログ<TechHarmony>を更新しました。Zabbix6.0.44、7.0.23、7.4.7までのバージョンに影響する脆弱性(CVE-2026-23926 ~ CVE-2026-23928)に関する情報です。https://blog.usize-tech.com/zabbix-vulnerabilities-202605/ #SCSK #Zabbix

    Post summary

    The blog post announces that Zabbix versions up to 6.0.44, 7.0.23, and 7.4.7 are affected by CVE-2026-23926 through CVE-2026-23928, with no exploit or patch information provided.

    00020453
    67 followersView on X
  • キタきつね@foxbook
    General

    Zabbixの脆弱性により、監視対象ホストが管理ダッシュボードを乗っ取ることが可能に Zabbix Flaws Allow Monitored Hosts to Hijack Admin Dashboards #DailyCyberSecurity (May 8) https://securityonline.info/zabbix-security-patches-xss-oracle-injection-cve-2026-23926/

    Post summary

    The article notes a Zabbix flaw that could let monitored hosts hijack admin dashboards, but provides no evidence of a PoC, exploit code, active attacks, patches, or detailed technical data.

    00020233
    4.9K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-23926 Authenticated JavaScript Injection in Host Navigator Widget Maintenance Period Tooltips https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-23926

    Post summary

    The content announces CVE-2026-23926, indicating an authenticated JavaScript injection vulnerability affecting the Host Navigator Widget Maintenance Period Tooltips, but provides no evidence of exploitation, proof‑of‑concept, or patch information.

    0000046
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appzabbixzabbix---

Explore more