Search Results (136 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-59788 1 Zabbix 1 Zabbix 2026-10-05 4.8 Medium
The email media type OAuth form passes the Authorization endpoint value to window.open() without validating the URL scheme, so a javascript: URL is executed in the browser. This means a crafted media type configuration, deliverable as an import file, runs arbitrary JavaScript as the Super Admin who grants consent.
CVE-2026-59787 1 Zabbix 1 Zabbix 2026-10-05 4.3 Medium
The Perl SNMP trap receiver script shipped with Zabbix does not properly neutralize the ZBXTRAP record delimiter in trap content. This means someone able to send SNMP traps can inject a record targeting another host, resulting in a loss of integrity.
CVE-2026-59786 1 Zabbix 1 Zabbix 2026-10-05 5.3 Medium
Zabbix Server and Proxy accept the active agent heartbeat message regardless of the configured PSK or certificate authentication. This means someone with access to the Zabbix trapper port can report an arbitrary host using an active agent as available, resulting in a loss of integrity.
CVE-2026-59785 1 Zabbix 1 Zabbix 2026-10-05 4.3 Medium
Host search in Frontend allows filtering by fields that are not displayed, including stored IPMI and PSK credentials. A user with read access can guess a credential and see from the search result whether the guess was right, letting them uncover it.
CVE-2026-59783 1 Zabbix 1 Zabbix 2026-10-05 6.5 Medium
The Zabbix Server/Proxy has a vulnerability where binary items can crash the Server/Proxy on certain NULL byte input leading to potential loss of availability. This only affects deployments where MySQL/MariaDB database is used as the Zabbix database.
CVE-2026-59782 1 Zabbix 1 Zabbix 2026-10-05 4.9 Medium
The JavaScript preprocessing (Duktape) engine on Zabbix server has a vulnerability where a limited administrator is able to read raw heap data potentially resulting in leaked data from other running preprocessors not available to said administrator.
CVE-2026-59781 1 Zabbix 1 Zabbix 2026-09-23 7.8 High
When Zabbix Agent was installed on Windows into a custom installation directory, the installer did not verify whether the selected directory had secure access permissions. If the target directory allowed unauthorized users to modify its contents, an attacker could place a malicious DLL that could later be loaded by the application, resulting in DLL sideloading. The installer has been hardened to detect potentially unsafe installation directories and now requires explicit user confirmation before proceeding with installation in such locations. This reduces the risk of accidental installation into directories with inappropriate permissions while preserving compatibility with existing deployment scenarios.
CVE-2026-23938 1 Zabbix 1 Zabbix 2026-09-23 4.9 Medium
An authenticated administrator is able to crash Zabbix server or proxy by creating specifically crafted preprocessing/script item JavaScript scripts, leading to potential denial of service.
CVE-2026-23931 1 Zabbix 1 Zabbix 2026-09-23 4.3 Medium
The frontend validatate.api.exists action can be exploited by authenticated users to extract plaintext user macro values leading to potential loss of confidentiality.
CVE-2026-23933 1 Zabbix 1 Zabbix 2026-09-23 9.1 Critical
In Zabbix 7.4 the cryptographic key used for signing Frontend sessions has been erroneously written to the database seed. Currently the only known exploitation scenario is for deployments that utilize both - SAML authentication and guest users. In such cases the key can be used to forge valid session cookies, potentially leading to unauthorized access. For other Zabbix deployments this does not have a known impact.
CVE-2026-23934 1 Zabbix 1 Zabbix 2026-09-23 6.5 Medium
An authenticated user is able to cause disproportionate CPU load on the Frontend webserver by sending specifically crafted requests to the Frontend validate.api.exists action, leading to potential denial of service.
CVE-2026-23935 1 Zabbix 1 Zabbix 2026-09-23 4.9 Medium
A Zabbix administrator is able to read out of bounds memory by utilizing a flaw in script item/preprocessing (JavaScript) HttpRequest logic, leading to potential confidentiality loss.
CVE-2026-23937 1 Zabbix 1 Zabbix 2026-09-23 6.5 Medium
The Zabbix API host.get action can be exploited by authenticated users to extract a host's PSK key leading to potential loss of data integrity.
CVE-2026-23919 1 Zabbix 1 Zabbix 2026-09-18 6.0 Medium
For performance reasons Zabbix Server/Proxy reuses JavaScript (Duktape) contexts (used in script items, JavaScript reprocessing, Webhooks). This can lead to confidentiality loss where a regular (non-super) Zabbix administrator leaks data for hosts they do not have access to. A fix has been released that makes the built in Zabbix JavaScript objects read-only, but please be advised that usage of global JavaScript variables is not recommended because their content could be leaked. More information <a href='https://www.zabbix.com/documentation/7.4/en/manual/installation/known_issues#preprocessing-global-variables-are-unsafe'>in Zabbix documentation</a>.
CVE-2026-23924 1 Zabbix 1 Zabbix 2026-09-18 4.9 Medium
Zabbix Agent 2 Docker plugin does not properly sanitize the 'docker.container_info' parameters when forwarding them to the Docker daemon. An attacker capable of invoking Agent 2 can read arbitrary files from running Docker containers by injecting them via the Docker archive API.
CVE-2026-23926 1 Zabbix 1 Zabbix 2026-09-18 6.8 Medium
An authenticated (non-super) administrator can create a maintenance period with a JavaScript payload that is executed by any user that opens tooltip for that maintenance period in the Host navigator widget. This can allow the attacker to perform unauthorized actions depending on which user opens the tooltip.
CVE-2026-23927 1 Zabbix 1 Zabbix 2026-09-18 6.5 Medium
A user able to connect to Agent 2 can inject an Oracle TNS connection string via the 'service' parameter. This can lead to Agent 2 connecting to an attacker-controlled server and leaking Oracle database credentials if they are saved in a named session.
CVE-2026-23928 1 Zabbix 1 Zabbix 2026-09-18 6.8 Medium
The Item history widget (in Zabbix 7.0+) or the Plain text widget (in Zabbix 6.0) can execute injected JavaScript when HTML display is enabled. This can allow an attacker to perform unauthorized actions depending on which user opens a dashboard containing these widgets. The malicious JavaScript would have to come from a monitored host controlled by the attacker. Note: the Item history widget is a replacement for the Plain text widget since Zabbix 7.0.
CVE-2026-23923 1 Zabbix 1 Zabbix 2026-09-10 5.3 Medium
An unauthenticated attacker can exploit the Frontend 'validate' action to blindly instantiate arbitrary PHP classes. The impact depends on environment setup but appears limited at this time.
CVE-2026-23920 1 Zabbix 1 Zabbix 2026-09-10 8.8 High
Host and event action script input is validated with a regex (set by the administrator), but the validation runs in multiline mode. If ^ and $ anchors are used in user input validation, an injected newline lets authenticated users bypass the check and inject shell commands.