For performance reasons Zabbix Server/Proxy reuses JavaScript (Duktape) contexts (used in script items, JavaScript reprocessing, Webhooks). This can lead to confidentiality loss where a regular (non-super) Zabbix administrator leaks data for hosts they do not have access to. A fix has been released that makes the built in Zabbix JavaScript objects read-only, but please be advised that usage of global JavaScript variables is not recommended because their content could be leaked. More information in Zabbix documentation.
{
"unresolved_ranges": [
{
"cpes": [
"cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "7.2.0"
},
{
"fixed": "7.2.13"
}
],
"source": "CPE_RANGE",
"vendor_product": "zabbix:zabbix"
}
]
}{
"cpe": "cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "6.0.0"
},
{
"fixed": "6.0.42"
},
{
"introduced": "7.0.0"
},
{
"fixed": "7.0.19"
},
{
"introduced": "7.4.0"
},
{
"fixed": "7.4.3"
}
],
"source": "CPE_RANGE"
}
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-23919.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"157727525753363784028529845487499435249",
"27409037118631387054794427538309179055",
"27798262849745551393995762901177891229",
"22395282881077179213628745305016054490",
"239699017004993772462648339958603615254",
"141402681887068849379089357001356861209"
],
"threshold": 0.9
},
"id": "CVE-2026-23919-7dd2354a",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/zabbix/zabbix/commit/6b0c021686541fa9adff0750822aff16d8f415dc",
"target": {
"file": "src/zabbix_java/src/com/zabbix/gateway/GeneralInformation.java"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"157727525753363784028529845487499435249",
"27409037118631387054794427538309179055",
"101887468747004264965926174099410419413",
"138202073808854914352591204805443424897",
"68550282938433308140577112963161232224",
"81207438004583696800627889170449077349"
],
"threshold": 0.9
},
"id": "CVE-2026-23919-c34683d4",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/zabbix/zabbix/commit/9c308d6f49cbb36fe3a1818f7257aa4a99874d72",
"target": {
"file": "src/zabbix_java/src/com/zabbix/gateway/GeneralInformation.java"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"157727525753363784028529845487499435249",
"27409037118631387054794427538309179055",
"293408518166868358606423160826807322913",
"122939951645959989084393623954902935730",
"37690447125853858377267509139493518126",
"31262256131815065773608683336819603295"
],
"threshold": 0.9
},
"id": "CVE-2026-23919-f7c1ccab",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/zabbix/zabbix/commit/a2d0368f1b9dd2466230e80d081c35e979ebcf24",
"target": {
"file": "src/zabbix_java/src/com/zabbix/gateway/GeneralInformation.java"
}
}
]
"2026-09-20T14:24:12Z"