CVE-2026-23926

⚪ Do wiadomości

Wykonanie złośliwego kodu w Host navigator widget umożliwia atakującemu przejęcie kontroli.

CVSS
6.8
EPSS
0.3%
Exploit
none
Vendor
zabbix
Opis źródłowy (NVD)

An authenticated (non-super) administrator can create a maintenance period with a JavaScript payload that is executed by any user that opens tooltip for that maintenance period in the Host navigator widget. This can allow the attacker to perform unauthorized actions depending on which user opens the tooltip.

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS6.8
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.3%
Opublikowano (NVD)2026-05-06 08:16:01 UTC
Ostatnia modyfikacja (NVD)2026-09-18 15:35:11 UTC
Referencje