CVE-2026-23919
published 2026-03-24CVE-2026-23919: For performance reasons Zabbix Server/Proxy reuses JavaScript (Duktape) contexts (used in script items, JavaScript reprocessing, Webhooks). This can lead to…
PriorityP425high7.1CVSS 4.0
AVAACLATPPRHUINVCHVILVALSCHSILSALEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.15%
5.0th percentile
For performance reasons Zabbix Server/Proxy reuses JavaScript (Duktape) contexts (used in script items, JavaScript reprocessing, Webhooks). This can lead to confidentiality loss where a regular (non-super) Zabbix administrator leaks data for hosts they do not have access to. A fix has been released that makes the built in Zabbix JavaScript objects read-only, but please be advised that usage of global JavaScript variables is not recommended because their content could be leaked. More information in Zabbix documentation.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | zabbix | < zabbix 1:7.0.22+dfsg-1 (forky) | zabbix 1:7.0.22+dfsg-1 (forky) |
| zabbix | zabbix | >= 0 < 1:7.0.22+dfsg-1~deb13u1 | 1:7.0.22+dfsg-1~deb13u1 |
| zabbix | zabbix | >= 0 < 1:7.0.22+dfsg-1 | 1:7.0.22+dfsg-1 |
| zabbix | zabbix | 6.0.0 – 6.0.41 | — |
| zabbix | zabbix | 7.0.0 – 7.0.18 | — |
| zabbix | zabbix | 7.2.0 – 7.2.12 | — |
| zabbix | zabbix | 7.4.0 – 7.4.2 | — |
CVSS provenance
nvdv4.07.1HIGHCVSS:4.0/AV:A/AC:L/AT:P/PR:H/UI:N/VC:H/VI:L/VA:L/SC:H/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv7.1HIGH
vendor_debian7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2026-23919: (For performance reasons Zabbix Server/Proxy reuses JavaScript (Duktape
osv·2026-04-06·CVSS 7.1
CVE-2026-23919 [HIGH] CVE-2026-23919: (For performance reasons Zabbix Server/Proxy reuses JavaScript (Duktape
(For performance reasons Zabbix Server/Proxy reuses JavaScript (Duktape ...)
OSV
CVE-2026-23919: For performance reasons Zabbix Server/Proxy reuses JavaScript (Duktape) contexts (used in script items, JavaScript reprocessing, Webhooks)
osv·2026-03-24·CVSS 7.1
CVE-2026-23919 [HIGH] CVE-2026-23919: For performance reasons Zabbix Server/Proxy reuses JavaScript (Duktape) contexts (used in script items, JavaScript reprocessing, Webhooks)
For performance reasons Zabbix Server/Proxy reuses JavaScript (Duktape) contexts (used in script items, JavaScript reprocessing, Webhooks). This can lead to confidentiality loss where a regular (non-super) Zabbix administrator leaks data for hosts they do not have access to. A fix has been released that makes the built in Zabbix JavaScript objects read-only, but please be advised that usage of global JavaScript variables is not recommended because their content could be leaked. More information in Zabbix documentation.
GHSA
GHSA-h55g-ww3m-9hq9: For performance reasons Zabbix Server/Proxy reuses JavaScript (Duktape) contexts (used in script items, JavaScript reprocessing, Webhooks)
ghsa_unreviewed·2026-03-24
CVE-2026-23919 [HIGH] CWE-488 GHSA-h55g-ww3m-9hq9: For performance reasons Zabbix Server/Proxy reuses JavaScript (Duktape) contexts (used in script items, JavaScript reprocessing, Webhooks)
For performance reasons Zabbix Server/Proxy reuses JavaScript (Duktape) contexts (used in script items, JavaScript reprocessing, Webhooks). This can lead to confidentiality loss where a regular (non-super) Zabbix administrator leaks data for hosts they do not have access to. A fix has been released that makes the built in Zabbix JavaScript objects read-only, but please be advised that usage of global JavaScript variables is not recommended because their content could be leaked. More information in Zabbix documentation.
Debian
CVE-2026-23919: zabbix - For performance reasons Zabbix Server/Proxy reuses JavaScript (Duktape) contexts...
vendor_debian·2026·CVSS 7.1
CVE-2026-23919 [HIGH] CVE-2026-23919: zabbix - For performance reasons Zabbix Server/Proxy reuses JavaScript (Duktape) contexts...
For performance reasons Zabbix Server/Proxy reuses JavaScript (Duktape) contexts (used in script items, JavaScript reprocessing, Webhooks). This can lead to confidentiality loss where a regular (non-super) Zabbix administrator leaks data for hosts they do not have access to. A fix has been released that makes the built in Zabbix JavaScript objects read-only, but please be advised that usage of global JavaScript variables is not recommended because their content could be leaked. More information in Zabbix documentation.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1:7.0.22+dfsg-1)
sid: resolved (fixed in 1:7.0.22+dfsg-1)
trixie: resolved (fixed in 1:7.0.22+dfsg-1~deb13u1)
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-23924 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.1
CVE-2026-23924 [HIGH] CVE-2026-23924 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-23924 :
Zabbix Server vulnerability analysis and mitigation
Zabbix Agent 2 Docker plugin does not properly sanitize the 'docker.container_info' parameters when forwarding them to the Docker daemon. An attacker capable of invoking Agent 2 can read arbitrary files from running Docker containers by injecting them via the Docker archive API.
Source : NVD
## 6.1
Score
Published March 24, 2026
Severity MEDIUM
CNA Score 6.1
Affected Technologies
Zabbix Server
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 17.7
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
zabbix
cpe:2.3:a:zabbix:zabbix
Sources
NVD
Debian 11, 12, 13, 14 No Fix Added at: M
Wiz
CVE-2026-23923 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.1
CVE-2026-23923 [HIGH] CVE-2026-23923 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-23923 :
Zabbix Server vulnerability analysis and mitigation
An unauthenticated attacker can exploit the Frontend 'validate' action to blindly instantiate arbitrary PHP classes. The impact depends on environment setup but appears limited at this time.
Source : NVD
## 6.9
Score
Published March 24, 2026
Severity MEDIUM
CNA Score 6.9
Affected Technologies
Zabbix Server
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 22
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
cpe:2.3:a:zabbix:zabbix
Sources
NVD
Linux No Fix Added at: Mar 26, 2026
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable,
Wiz
CVE-2026-23925 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.1
CVE-2026-23925 [HIGH] CVE-2026-23925 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-23925 :
Zabbix Server vulnerability analysis and mitigation
An authenticated Zabbix user (User role) with template/host write permissions is able to create objects via the configuration.import API. This can lead to confidentiality loss by creating unauthorized hosts. Note that the User role is normally not sufficient to create and edit templates/hosts even with write permissions.
Source : NVD
## 5.1
Score
Published March 6, 2026
Severity MEDIUM
CNA Score 5.1
Affected Technologies
Zabbix Server
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
zabbix
cpe:2.3:a:zabbix:zabbix
Sources
NVD
Wiz
CVE-2026-23920 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.1
CVE-2026-23920 [HIGH] CVE-2026-23920 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-23920 :
Zabbix Server vulnerability analysis and mitigation
Host and event action script input is validated with a regex (set by the administrator), but the validation runs in multiline mode. If ^ and $ anchors are used in user input validation, an injected newline lets authenticated users bypass the check and inject shell commands.
Source : NVD
## 7.7
Score
Published March 24, 2026
Severity HIGH
CNA Score 7.7
Affected Technologies
Zabbix Server
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 16.3
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
zabbix
cpe:2.3:a:zabbix:zabbix
Sources
NVD
Debian 11, 12 No Fix Added at: Mar 29, 2026
De
Wiz
CVE-2026-23921 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.1
CVE-2026-23921 [HIGH] CVE-2026-23921 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-23921 :
Zabbix Server vulnerability analysis and mitigation
A low privilege Zabbix user with API access can exploit a blind SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary SQL selects via the sortfield parameter. Although query results are not returned directly, an attacker can exfiltrate arbitrary database data through time-based techniques, potentially leading to session identifier disclosure and administrator account compromise.
Source : NVD
## 8.7
Score
Published March 24, 2026
Severity HIGH
CNA Score 8.7
Affected Technologies
Zabbix Server
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 9.7
Exploitation Probability
Wiz
CVE-2026-23919 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.1
CVE-2026-23919 [HIGH] CVE-2026-23919 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-23919 :
Zabbix Server vulnerability analysis and mitigation
For performance reasons Zabbix Server/Proxy reuses JavaScript (Duktape) contexts (used in script items, JavaScript reprocessing, Webhooks). This can lead to confidentiality loss where a regular (non-super) Zabbix administrator leaks data for hosts they do not have access to. A fix has been released that makes the built in Zabbix JavaScript objects read-only, but please be advised that usage of global JavaScript variables is not recommended because their content could be leaked. More information in Zabbix documentation .
Source : NVD
## 7.1
Score
Published March 24, 2026
Severity HIGH
CNA Score 7.1
Affected Technologies
Zabbix Server
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Rel
Bugzilla
CVE-2026-23919 zabbix7.0: Zabbix Server and Proxy: Information disclosure via reused JavaScript contexts [epel-all]
bugzilla·2026-03-24·CVSS 7.1
CVE-2026-23919 [HIGH] CVE-2026-23919 zabbix7.0: Zabbix Server and Proxy: Information disclosure via reused JavaScript contexts [epel-all]
CVE-2026-23919 zabbix7.0: Zabbix Server and Proxy: Information disclosure via reused JavaScript contexts [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
https://support.zabbix.com/browse/ZBX-27638
Bugzilla
CVE-2026-23919 zabbix6.0: Zabbix Server and Proxy: Information disclosure via reused JavaScript contexts [epel-all]
bugzilla·2026-03-24·CVSS 7.1
CVE-2026-23919 [HIGH] CVE-2026-23919 zabbix6.0: Zabbix Server and Proxy: Information disclosure via reused JavaScript contexts [epel-all]
CVE-2026-23919 zabbix6.0: Zabbix Server and Proxy: Information disclosure via reused JavaScript contexts [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
https://support.zabbix.com/browse/ZBX-27638
Bugzilla
CVE-2026-23919 zabbix: Zabbix Server and Proxy: Information disclosure via reused JavaScript contexts [epel-all]
bugzilla·2026-03-24·CVSS 7.1
CVE-2026-23919 [HIGH] CVE-2026-23919 zabbix: Zabbix Server and Proxy: Information disclosure via reused JavaScript contexts [epel-all]
CVE-2026-23919 zabbix: Zabbix Server and Proxy: Information disclosure via reused JavaScript contexts [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
2026-03-24
Published