Junglewise Threat Intelligence

CVE-2026-23938: Zabbix Server and Proxy denial of service via JavaScript preprocessing

CVE-2026-23938 · Severity: medium · CVSS 4.9 · Published 2026-08-18

Vendors: Zabbix.

Executive brief

Zabbix Server and Proxy are monitoring and network management solutions used by organizations to track infrastructure health and performance. An authenticated administrator can crash these services by submitting malicious JavaScript code in preprocessing or script item configurations, causing service outages and loss of monitoring visibility. The attack requires privileged administrative access and results in temporary denial of service.

Technical details

This vulnerability is a denial-of-service condition in Zabbix Server and Proxy triggered by improper handling of specifically crafted JavaScript code in preprocessing and script item configurations. The vulnerability affects the JavaScript execution engine when processing administrator-supplied preprocessing or script payloads, allowing a crash of the server or proxy process. An authenticated administrator account (non-super admin with sufficient privileges) is required to exploit this vulnerability, and successful exploitation results in temporary unavailability of the monitoring infrastructure. Patches are available for all affected branches: 6.0.47, 7.0.27, and 7.4.11.

Affected products

  • Zabbix Zabbix Server 6.0.0–6.0.46, 7.0.0–7.0.26, 7.4.0–7.4.10
  • Zabbix Zabbix Proxy 6.0.0–6.0.46, 7.0.0–7.0.26, 7.4.0–7.4.10

Timeline

  • 2026-08-18: disclosed: Vulnerability published
  • 2026-08-18: patched: Fixes released: 6.0.47, 7.0.27, 7.4.11

References

Related threats