CVE-2026-23920
published 2026-03-24CVE-2026-23920: Host and event action script input is validated with a regex (set by the administrator), but the validation runs in multiline mode. If ^ and $ anchors are used…
PriorityP346high7.7CVSS 4.0
AVNACLATPPRLUINVCHVIHVAHSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.25%
16.1th percentile
Host and event action script input is validated with a regex (set by the administrator), but the validation runs in multiline mode. If ^ and $ anchors are used in user input validation, an injected newline lets authenticated users bypass the check and inject shell commands.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | zabbix | < zabbix 1:7.0.22+dfsg-1 (forky) | zabbix 1:7.0.22+dfsg-1 (forky) |
| zabbix | zabbix | >= 0 < 1:7.0.22+dfsg-1~deb13u1 | 1:7.0.22+dfsg-1~deb13u1 |
| zabbix | zabbix | >= 0 < 1:7.0.22+dfsg-1 | 1:7.0.22+dfsg-1 |
| zabbix | zabbix | 7.0.0 – 7.0.21 | — |
| zabbix | zabbix | 7.2.0 – 7.2.14 | — |
| zabbix | zabbix | 7.4.0 – 7.4.5 | — |
CVSS provenance
nvdv4.07.7HIGHCVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv7.7HIGH
vendor_debian7.7HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2026-23920: (Host and event action script input is validated with a regex (set by t
osv·2026-04-06·CVSS 7.7
CVE-2026-23920 [HIGH] CVE-2026-23920: (Host and event action script input is validated with a regex (set by t
(Host and event action script input is validated with a regex (set by t ...)
GHSA
GHSA-2h5x-h7x4-hm9h: Host and event action script input is validated with a regex (set by the administrator), but the validation runs in multiline mode
ghsa_unreviewed·2026-03-24
CVE-2026-23920 [HIGH] CWE-78 GHSA-2h5x-h7x4-hm9h: Host and event action script input is validated with a regex (set by the administrator), but the validation runs in multiline mode
Host and event action script input is validated with a regex (set by the administrator), but the validation runs in multiline mode. If ^ and $ anchors are used in user input validation, an injected newline lets authenticated users bypass the check and inject shell commands.
OSV
CVE-2026-23920: Host and event action script input is validated with a regex (set by the administrator), but the validation runs in multiline mode
osv·2026-03-24·CVSS 7.7
CVE-2026-23920 [HIGH] CVE-2026-23920: Host and event action script input is validated with a regex (set by the administrator), but the validation runs in multiline mode
Host and event action script input is validated with a regex (set by the administrator), but the validation runs in multiline mode. If ^ and $ anchors are used in user input validation, an injected newline lets authenticated users bypass the check and inject shell commands.
Debian
CVE-2026-23920: zabbix - Host and event action script input is validated with a regex (set by the adminis...
vendor_debian·2026·CVSS 7.7
CVE-2026-23920 [HIGH] CVE-2026-23920: zabbix - Host and event action script input is validated with a regex (set by the adminis...
Host and event action script input is validated with a regex (set by the administrator), but the validation runs in multiline mode. If ^ and $ anchors are used in user input validation, an injected newline lets authenticated users bypass the check and inject shell commands.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1:7.0.22+dfsg-1)
sid: resolved (fixed in 1:7.0.22+dfsg-1)
trixie: resolved (fixed in 1:7.0.22+dfsg-1~deb13u1)
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-23924 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.1
CVE-2026-23924 [HIGH] CVE-2026-23924 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-23924 :
Zabbix Server vulnerability analysis and mitigation
Zabbix Agent 2 Docker plugin does not properly sanitize the 'docker.container_info' parameters when forwarding them to the Docker daemon. An attacker capable of invoking Agent 2 can read arbitrary files from running Docker containers by injecting them via the Docker archive API.
Source : NVD
## 6.1
Score
Published March 24, 2026
Severity MEDIUM
CNA Score 6.1
Affected Technologies
Zabbix Server
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 17.7
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
zabbix
cpe:2.3:a:zabbix:zabbix
Sources
NVD
Debian 11, 12, 13, 14 No Fix Added at: M
Wiz
CVE-2026-23923 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.1
CVE-2026-23923 [HIGH] CVE-2026-23923 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-23923 :
Zabbix Server vulnerability analysis and mitigation
An unauthenticated attacker can exploit the Frontend 'validate' action to blindly instantiate arbitrary PHP classes. The impact depends on environment setup but appears limited at this time.
Source : NVD
## 6.9
Score
Published March 24, 2026
Severity MEDIUM
CNA Score 6.9
Affected Technologies
Zabbix Server
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 22
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
cpe:2.3:a:zabbix:zabbix
Sources
NVD
Linux No Fix Added at: Mar 26, 2026
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable,
Wiz
CVE-2026-23925 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.1
CVE-2026-23925 [HIGH] CVE-2026-23925 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-23925 :
Zabbix Server vulnerability analysis and mitigation
An authenticated Zabbix user (User role) with template/host write permissions is able to create objects via the configuration.import API. This can lead to confidentiality loss by creating unauthorized hosts. Note that the User role is normally not sufficient to create and edit templates/hosts even with write permissions.
Source : NVD
## 5.1
Score
Published March 6, 2026
Severity MEDIUM
CNA Score 5.1
Affected Technologies
Zabbix Server
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
zabbix
cpe:2.3:a:zabbix:zabbix
Sources
NVD
Wiz
CVE-2026-23920 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.1
CVE-2026-23920 [HIGH] CVE-2026-23920 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-23920 :
Zabbix Server vulnerability analysis and mitigation
Host and event action script input is validated with a regex (set by the administrator), but the validation runs in multiline mode. If ^ and $ anchors are used in user input validation, an injected newline lets authenticated users bypass the check and inject shell commands.
Source : NVD
## 7.7
Score
Published March 24, 2026
Severity HIGH
CNA Score 7.7
Affected Technologies
Zabbix Server
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 16.3
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
zabbix
cpe:2.3:a:zabbix:zabbix
Sources
NVD
Debian 11, 12 No Fix Added at: Mar 29, 2026
De
Wiz
CVE-2026-23921 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.1
CVE-2026-23921 [HIGH] CVE-2026-23921 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-23921 :
Zabbix Server vulnerability analysis and mitigation
A low privilege Zabbix user with API access can exploit a blind SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary SQL selects via the sortfield parameter. Although query results are not returned directly, an attacker can exfiltrate arbitrary database data through time-based techniques, potentially leading to session identifier disclosure and administrator account compromise.
Source : NVD
## 8.7
Score
Published March 24, 2026
Severity HIGH
CNA Score 8.7
Affected Technologies
Zabbix Server
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 9.7
Exploitation Probability
Wiz
CVE-2026-23919 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.1
CVE-2026-23919 [HIGH] CVE-2026-23919 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-23919 :
Zabbix Server vulnerability analysis and mitigation
For performance reasons Zabbix Server/Proxy reuses JavaScript (Duktape) contexts (used in script items, JavaScript reprocessing, Webhooks). This can lead to confidentiality loss where a regular (non-super) Zabbix administrator leaks data for hosts they do not have access to. A fix has been released that makes the built in Zabbix JavaScript objects read-only, but please be advised that usage of global JavaScript variables is not recommended because their content could be leaked. More information in Zabbix documentation .
Source : NVD
## 7.1
Score
Published March 24, 2026
Severity HIGH
CNA Score 7.1
Affected Technologies
Zabbix Server
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Rel
Bugzilla
CVE-2026-23920 zabbix: Zabbix: Arbitrary code execution via newline injection in script input validation [epel-all]
bugzilla·2026-03-24·CVSS 7.7
CVE-2026-23920 [HIGH] CVE-2026-23920 zabbix: Zabbix: Arbitrary code execution via newline injection in script input validation [epel-all]
CVE-2026-23920 zabbix: Zabbix: Arbitrary code execution via newline injection in script input validation [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-23920 zabbix7.0: Zabbix: Arbitrary code execution via newline injection in script input validation [epel-all]
bugzilla·2026-03-24·CVSS 7.7
CVE-2026-23920 [HIGH] CVE-2026-23920 zabbix7.0: Zabbix: Arbitrary code execution via newline injection in script input validation [epel-all]
CVE-2026-23920 zabbix7.0: Zabbix: Arbitrary code execution via newline injection in script input validation [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
https://support.zabbix.com/browse/ZBX-27639
Bugzilla
CVE-2026-23920 zabbix6.0: Zabbix: Arbitrary code execution via newline injection in script input validation [epel-all]
bugzilla·2026-03-24·CVSS 7.7
CVE-2026-23920 [HIGH] CVE-2026-23920 zabbix6.0: Zabbix: Arbitrary code execution via newline injection in script input validation [epel-all]
CVE-2026-23920 zabbix6.0: Zabbix: Arbitrary code execution via newline injection in script input validation [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
https://support.zabbix.com/browse/ZBX-27639 does not show 6.0 as being affected.
2026-03-24
Published