Prototype pollution vulnerability in searchParamsToObject() is leading to a persistent XSS in Maps. URL parameter processing was not filtering dangerous properties like proto, combined with jQuery's unsafe element creation that traversed the prototype chain.
{
"cpe": "cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "6.0.0"
},
{
"fixed": "6.0.46"
},
{
"introduced": "7.0.0"
},
{
"fixed": "7.0.25"
},
{
"introduced": "7.4.0"
},
{
"fixed": "7.4.9"
}
],
"source": "CPE_RANGE"
}
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-23929.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"136106974676500628095819384296506580184",
"189079620011086932739101496157153831730",
"17796007570490054293463654449847667250",
"202479199046539095102022445937485727892",
"239101855245159906132380048241102823909",
"224016063001519858635466180994184907584"
],
"threshold": 0.9
},
"id": "CVE-2026-23929-30a9ca0d",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/zabbix/zabbix/commit/75bd32d3d61309bf44008b7de9d40d5ba4aeed8c",
"target": {
"file": "src/zabbix_java/src/com/zabbix/gateway/GeneralInformation.java"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"136106974676500628095819384296506580184",
"189079620011086932739101496157153831730",
"36490162052462539846518614666067146469",
"62656957665135650188906633860546473017",
"268279169556215922868823285013647302698",
"236962407826193720376950051496116172935"
],
"threshold": 0.9
},
"id": "CVE-2026-23929-cec2296b",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/zabbix/zabbix/commit/d607227714fc00ec6117e663d0934cb90c0f842b",
"target": {
"file": "src/zabbix_java/src/com/zabbix/gateway/GeneralInformation.java"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"251298476628956666898959397427583219885",
"317395765437267642752885460754421906832",
"246560037484377983876553518236791968213",
"132857211799543049662189930037710632272",
"226753002036689452187127334565521006179",
"258424649166307181966099817385825166269"
],
"threshold": 0.9
},
"id": "CVE-2026-23929-da87e516",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/zabbix/zabbix/commit/cee258041801bce58269e37677a1b86c9fde629c",
"target": {
"file": "src/zabbix_java/src/com/zabbix/gateway/GeneralInformation.java"
}
}
]
"2026-09-10T08:13:46Z"