216.73.216.36

CVE-2026-23928

· Published 06/05/2026 08:16 · Modified 06/05/2026 08:16

Labels: CVE-2026-23928 2026-05-06CVE-2026-23928CWE-79[email protected]

Essential information

Published
06/05/2026 08:16
Modified
06/05/2026 08:16
Author
Creator
CVSS
7.3 HIGH (v3) 7.3 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

The Item history widget (in Zabbix 7.0+) or the Plain text widget (in Zabbix 6.0) can execute injected JavaScript when HTML display is enabled. This can allow an attacker to perform unauthorized actions depending on which user opens a dashboard containing these widgets. The malicious JavaScript would have to come from a monitored host controlled by the attacker. Note: the Item history widget is a replacement for the Plain text widget since Zabbix 7.0.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
zabbix / zabbix cpe:2.3:a:zabbix:zabbix:7.0.*:*:*:*:*:*:*:*
zabbix / zabbix cpe:2.3:a:zabbix:zabbix:6.0:*:*:*:*:*:*:*

References