Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-23938

Опубликовано: 18 авг. 2026
Источник: redhat
CVSS3: 2.7
EPSS Низкий

Описание

A flaw was found in Zabbix. An authenticated administrator can exploit this vulnerability by creating specially crafted JavaScript scripts within preprocessing or script items. This can lead to a denial of service (DoS) by crashing the Zabbix server or proxy.

Отчет

Zabbix is not shipped in any Red Hat product. This flaw affects community packages in Fedora and EPEL only.

Меры по смягчению последствий

Restrict administrative access to trusted users only. Review and audit JavaScript preprocessing and script items configured on the Zabbix server.

Дополнительная информация

Статус:

Low
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2517809zabbix: Zabbix: Denial of Service via crafted JavaScript scripts

EPSS

Процентиль: 22%
0.00298
Низкий

2.7 Low

CVSS3

Связанные уязвимости

ubuntu
2 дня назад

(An authenticated administrator is able to crash Zabbix server or proxy ...)

nvd
2 дня назад

An authenticated administrator is able to crash Zabbix server or proxy by creating specifically crafted preprocessing/script item JavaScript scripts, leading to potential denial of service.

debian
2 дня назад

An authenticated administrator is able to crash Zabbix server or proxy ...

github
2 дня назад

An authenticated administrator is able to crash Zabbix server or proxy by creating specifically crafted preprocessing/script item JavaScript scripts, leading to potential denial of service.

EPSS

Процентиль: 22%
0.00298
Низкий

2.7 Low

CVSS3