Junglewise Threat Intelligence

CVE-2026-23935: Zabbix Server use-after-free read in HttpRequest

CVE-2026-23935 · Severity: medium · CVSS 4.9 · Published 2026-08-18

Vendors: Zabbix.

Executive brief

Zabbix Server is a monitoring and alerting platform used by IT teams to track infrastructure health. An authenticated administrator can exploit a flaw in the JavaScript preprocessing/script item functionality to read sensitive data from server memory, potentially exposing API keys, credentials, or other confidential information stored in the process.

Technical details

This is a use-after-free vulnerability in the Zabbix Server's JavaScript HttpRequest implementation used for script items and preprocessing scripts. An authenticated administrator can craft malicious JavaScript preprocessing scripts to trigger an out-of-bounds memory read via the HttpRequest body logic. The attack requires administrative privileges and no user interaction. Successful exploitation allows reading arbitrary memory contents from the Zabbix Server process, leading to confidentiality loss. The vulnerability affects versions 7.0.0–7.0.27 and 7.4.0–7.4.11, with fixes available in 7.0.28 and 7.4.12 respectively.

Affected products

  • Zabbix Server 7.0.0–7.0.27, 7.4.0–7.4.11

Timeline

  • 2026-08-18: disclosed
  • 2026-08-18: patched: Fixed in 7.0.28 and 7.4.12

References