CVE-2026-23926

EUVD-2026-27527
An authenticated (non-super) administrator can create a maintenance period with a JavaScript payload that is executed by any user that opens tooltip for that maintenance period in the Host navigator widget. This can allow the attacker to perform unauthorized actions depending on which user opens the tooltip.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.8 MEDIUM
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 18.44%
Affected Products (NVD)
VendorProductVersion
zabbixzabbix
7.0.0 ≤
𝑥
< 7.0.24
zabbixzabbix
7.4.0 ≤
𝑥
< 7.4.8
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
zabbix
bookworm
ignored
forky
1:7.0.29+dfsg-2
fixed
sid
1:7.0.29+dfsg-2
fixed
trixie
ignored
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
zabbix
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
dne
questing
ignored
resolute
needs-triage
trusty
needs-triage
xenial
needs-triage