Executive brief
Zabbix Server is a monitoring and alerting platform used by IT teams to track infrastructure health. An authenticated administrator can exploit a flaw in the JavaScript preprocessing/script item functionality to read sensitive data from server memory, potentially exposing API keys, credentials, or other confidential information stored in the process.
Technical details
This is a use-after-free vulnerability in the Zabbix Server's JavaScript HttpRequest implementation used for script items and preprocessing scripts. An authenticated administrator can craft malicious JavaScript preprocessing scripts to trigger an out-of-bounds memory read via the HttpRequest body logic. The attack requires administrative privileges and no user interaction. Successful exploitation allows reading arbitrary memory contents from the Zabbix Server process, leading to confidentiality loss. The vulnerability affects versions 7.0.0–7.0.27 and 7.4.0–7.4.11, with fixes available in 7.0.28 and 7.4.12 respectively.
Affected products
- Zabbix Server 7.0.0–7.0.27, 7.4.0–7.4.11
Timeline
- 2026-08-18: disclosed
- 2026-08-18: patched: Fixed in 7.0.28 and 7.4.12