CVE-2026-23926
⚪ Do wiadomości
Wykonanie złośliwego kodu w Host navigator widget umożliwia atakującemu przejęcie kontroli.
CVSS
6.8
EPSS
0.3%
Exploit
none
Vendor
zabbix
Opis źródłowy (NVD)
An authenticated (non-super) administrator can create a maintenance period with a JavaScript payload that is executed by any user that opens tooltip for that maintenance period in the Host navigator widget. This can allow the attacker to perform unauthorized actions depending on which user opens the tooltip.
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 6.8 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.3% |
| Opublikowano (NVD) | 2026-05-06 08:16:01 UTC |
| Ostatnia modyfikacja (NVD) | 2026-09-18 15:35:11 UTC |
Referencje
- https://support.zabbix.com/browse/ZBX-27758 ([email protected]) [Vendor Advisory]