CVE-2026-23935
Received Received - Intake

Out-of-Bounds Memory Read in Zabbix via Script Item Preprocessing

Vulnerability report for CVE-2026-23935, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-18

Last updated on: 2026-08-18

Assigner: Zabbix

Description

A Zabbix administrator is able to read out of bounds memory by utilizing a flaw in script item/preprocessing (JavaScript) HttpRequest logic, leading to potential confidentiality loss.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-18
Last Modified
2026-08-18
Generated
2026-08-18
AI Q&A
2026-08-18
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
zabbix zabbix *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

A Zabbix administrator can exploit a flaw in script item or preprocessing (JavaScript) HttpRequest logic to read out-of-bounds memory. This may result in unauthorized access to sensitive data, compromising confidentiality.

Detection Guidance

This vulnerability involves out-of-bounds memory read in Zabbix script item/preprocessing (JavaScript) HttpRequest logic. Detection requires checking Zabbix server and agent configurations for exposed JavaScript preprocessing rules or script items that may trigger this flaw. Review Zabbix frontend for any custom JavaScript preprocessing steps or script items using HttpRequest functions.

Impact Analysis

If you are a Zabbix administrator, an attacker could exploit this flaw to access sensitive information stored in memory, potentially leading to data breaches or unauthorized disclosure of confidential data.

Compliance Impact

This vulnerability could lead to unauthorized access to personal or sensitive data, violating GDPR and HIPAA compliance requirements. Organizations may face legal penalties, reputational damage, and loss of trust due to data exposure.

Mitigation Strategies

Update Zabbix to the latest patched version immediately to address the out-of-bounds memory read flaw in script item preprocessing. Disable JavaScript HttpRequest logic in scripts if not required. Restrict administrative access to Zabbix to minimize attack surface.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-23935. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart