CVE-2026-23928Disclosure(zabbix / zabbix)

LOWCVSS 6.8 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Item history widget (in Zabbix 7.0+) or the Plain text widget (in Zabbix 6.0) can execute injected JavaScript when HTML display is enabled. This can allow an attacker to perform unauthorized actions depending on which user opens a dashboard containing these widgets. The malicious JavaScript would have to come from a monitored host controlled by the attacker. Note: the Item history widget is a replacement for the Plain text widget since Zabbix 7.0.

0.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • zabbix

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-05-06); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
zabbix

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-05-06: 1Mentions · 2026-05-11: 1Mentions · 2026-05-31: 1Technical Details · 2026-05-06: 105-0605-1105-31
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-061
Disclosure1
2026-05-111
General1
2026-05-311
Disclosure1
Full discourse3 posts
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Zabbix ❗ CVE-2026-23928 ❗ CVE-2026-23926 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-zabbix-2/ https://t.co/hmJvPi9Vw7

    Post summary

    The tweet announces two CVEs related to Zabbix products and links to external resources for more information, but provides no additional technical, exploit, or patch details.

    00021137
    6.7K followersView on X
  • 【公式】SCSK Zabbix@SCSK_Zabbix
    Disclosure

    ★ 【緊急】26年5月公開のZabbix の脆弱性情報 ★ 弊社ブログ<TechHarmony>を更新しました。Zabbix6.0.44、7.0.23、7.4.7までのバージョンに影響する脆弱性(CVE-2026-23926 ~ CVE-2026-23928)に関する情報です。https://blog.usize-tech.com/zabbix-vulnerabilities-202605/ #SCSK #Zabbix

    Post summary

    The post announces the discovery of CVE‑2026‑23926 through CVE‑2026‑23928 vulnerabilities affecting Zabbix 6.0.44, 7.0.23, and 7.4.7 and directs readers to a company blog for further details.

    00020453
    67 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-23928 Cross-Site Scripting in Zabbix Item History and Plain Text Widgets https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-23928

    Post summary

    The text announces CVE‑2026‑23928 as a cross‑site scripting flaw in Zabbix’s Item History and Plain Text Widgets, linking to a database entry for more details.

    0000055
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appzabbixzabbix---

Explore more