CVE-2026-23938: Zabbix

Medium severity, CVSS 4.9. EPSS: 0.4% chance of exploitation in the next 30 days.

An authenticated administrator is able to crash Zabbix server or proxy by creating specifically crafted preprocessing/script item JavaScript scripts, leading to potential denial of service.

Affected products

  • Zabbix Zabbix: from 6.0.0, before 6.0.47 (fixed in 6.0.47); from 7.0.0, before 7.0.27 (fixed in 7.0.27); from 7.4.0, before 7.4.11 (fixed in 7.4.11)

Published 2026-08-18. Last modified 2026-09-23.