CVE-2026-23919 is a high-severity confidentiality vulnerability affecting Zabbix Server/Proxy, where the reuse of JavaScript contexts can allow a regular Zabbix administrator to leak data from hosts they are not authorized to access. This vulnerability carries a CVSSv4 score of 7.1 (High), requiring high privileges on an adjacent network but with low attack complexity and no user interaction, primarily leading to significant data confidentiality loss. Although a fix has been released to mitigate some aspects, the use of global JavaScript variables is still not recommended due to potential leakage. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.0.0, <= 6.0.41CPE match | cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:* | ||
>= 7.0.0, <= 7.0.18CPE match | cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:* | ||
>= 7.2.0, <= 7.2.12CPE match | cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:* | ||
>= 7.4.0, <= 7.4.2CPE match | cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:A/AC:L/AT:P/PR:H/UI:N/VC:H/VI:L/VA:L/SC:H/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.