CVE-2026-23928

Source
https://cve.org/CVERecord?id=CVE-2026-23928
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-23928.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-23928
Downstream
Published
2026-05-06T08:16:03Z
Modified
2026-09-20T14:24:12Z
Severity
  • 6.8 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

The Item history widget (in Zabbix 7.0+) or the Plain text widget (in Zabbix 6.0) can execute injected JavaScript when HTML display is enabled. This can allow an attacker to perform unauthorized actions depending on which user opens a dashboard containing these widgets. The malicious JavaScript would have to come from a monitored host controlled by the attacker. Note: the Item history widget is a replacement for the Plain text widget since Zabbix 7.0.

References

Affected packages

Git / github.com/zabbix/zabbix

Affected ranges

Type
GIT
Repo
https://github.com/zabbix/zabbix
Events
Database specific
Show details
{
    "cpe":  "cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:*",
    "extracted_events":  [
        {
            "introduced":  "6.0.0"
        },
        {
            "fixed":  "6.0.45"
        },
        {
            "introduced":  "7.0.0"
        },
        {
            "fixed":  "7.0.24"
        },
        {
            "introduced":  "7.4.0"
        },
        {
            "fixed":  "7.4.8"
        }
    ],
    "source":  "CPE_RANGE"
}

Affected versions

6.*
6.0.0
6.0.1
6.0.10
6.0.10rc1
6.0.10rc2
6.0.11
6.0.11rc1
6.0.11rc2
6.0.12
6.0.12rc1
6.0.12rc2
6.0.13
6.0.13rc1
6.0.14
6.0.14rc1
6.0.14rc2
6.0.15
6.0.15rc1
6.0.15rc2
6.0.16
6.0.16rc1
6.0.17
6.0.17rc1
6.0.17rc2
6.0.18
6.0.18rc1
6.0.19
6.0.19rc1
6.0.1rc1
6.0.1rc2
6.0.1rc3
6.0.1rc4
6.0.2
6.0.20
6.0.20rc1
6.0.21
6.0.21rc1
6.0.22
6.0.22rc1
6.0.23
6.0.23rc1
6.0.25
6.0.25rc1
6.0.26
6.0.26rc1
6.0.27
6.0.27rc1
6.0.28
6.0.28rc1
6.0.29
6.0.29rc1
6.0.2rc1
6.0.3
6.0.30
6.0.30rc1
6.0.31
6.0.31rc1
6.0.32
6.0.32rc1
6.0.33
6.0.33rc1
6.0.34
6.0.34rc1
6.0.34rc2
6.0.35
6.0.35rc1
6.0.36
6.0.36rc1
6.0.37
6.0.37rc1
6.0.38
6.0.38rc1
6.0.39
6.0.39rc1
6.0.3rc1
6.0.4
6.0.40
6.0.40rc1
6.0.41
6.0.41rc1
6.0.42
6.0.42rc1
6.0.43
6.0.43rc1
6.0.44
6.0.44rc1
6.0.45rc1
6.0.4rc1
6.0.5
6.0.5rc1
6.0.6
6.0.6rc1
6.0.7
6.0.7rc1
6.0.8
6.0.8rc1
6.0.8rc2
6.0.9
6.0.9rc1
6.0.9rc2
7.*
7.0.0
7.0.1
7.0.10
7.0.10rc1
7.0.11
7.0.11rc1
7.0.11rc2
7.0.12
7.0.12rc1
7.0.13
7.0.13rc1
7.0.14
7.0.14rc1
7.0.15
7.0.16
7.0.17
7.0.17rc1
7.0.17rc2
7.0.18
7.0.18rc1
7.0.18rc2
7.0.19
7.0.19rc1
7.0.1rc1
7.0.1rc2
7.0.2
7.0.20
7.0.20rc1
7.0.21
7.0.22
7.0.22rc1
7.0.22rc2
7.0.22rc3
7.0.23
7.0.23rc1
7.0.23rc2
7.0.24rc1
7.0.24rc2
7.0.24rc3
7.0.2rc1
7.0.2rc2
7.0.3
7.0.3rc1
7.0.4
7.0.4rc1
7.0.5
7.0.5rc1
7.0.6
7.0.6rc1
7.0.7
7.0.7rc1
7.0.8
7.0.8rc1
7.0.8rc2
7.0.9
7.0.9rc1
7.0.9rc2
7.4.0
7.4.1
7.4.1rc1
7.4.2
7.4.2rc1
7.4.2rc2
7.4.3
7.4.3rc1
7.4.4
7.4.4rc1
7.4.5
7.4.6
7.4.6rc1
7.4.6rc2
7.4.7
7.4.7rc1
7.4.7rc2
7.4.7rc3
7.4.8rc1
7.4.8rc2
7.4.8rc3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-23928.json"
vanir_signatures
[
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "2575989339259640105311353590351376328",
                "261745388088049729003388450910874131284",
                "78615119555629258408370069502963169562",
                "106265636532305374733445754623506502550",
                "142981670864924541529460717571059194747",
                "276456720699755867738555225603931221904"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-23928-3c3866b9",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/zabbix/zabbix/commit/6b0f6b25da00d2c2a0dc2035ba2285aa51c85865",
        "target":  {
            "file":  "src/zabbix_java/src/com/zabbix/gateway/GeneralInformation.java"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "13006993947316681917700725759978790726",
                "246202365619345375288485124626876863591",
                "211408096376471392416611541472284431260",
                "270294714855371664368322160720009475489",
                "60583027902879434151887895598095070927",
                "190443916206833154001079149101507226106"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-23928-84ec59d2",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/zabbix/zabbix/commit/d8c5768f7d09e99586d81237c2c891ce20280cc8",
        "target":  {
            "file":  "src/zabbix_java/src/com/zabbix/gateway/GeneralInformation.java"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "328694341909655700810807882163230140941",
                "12061819213497335241319149757757382988",
                "8781501731097225876935453466613140553",
                "132482256639643116861018651525990961205",
                "188121564415475832297632590253969155136",
                "36080719019429417973525356404344529663"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-23928-92c6c503",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/zabbix/zabbix/commit/36bdd34b378e8731c7c825df38c364e00a76e6a5",
        "target":  {
            "file":  "src/zabbix_java/src/com/zabbix/gateway/GeneralInformation.java"
        }
    }
]
vanir_signatures_modified
"2026-09-20T14:24:12Z"