CVE-2026-23938
Received Received - Intake

Denial of Service in Zabbix via Malicious JavaScript Preprocessing

Vulnerability report for CVE-2026-23938, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-18

Last updated on: 2026-08-18

Assigner: Zabbix

Description

An authenticated administrator is able to crash Zabbix server or proxy by creating specifically crafted preprocessing/script item JavaScript scripts, leading to potential denial of service.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-18
Last Modified
2026-08-18
Generated
2026-08-18
AI Q&A
2026-08-18
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
zabbix zabbix *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-248 An exception is thrown from a function, but it is not caught.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows an authenticated administrator to crash the Zabbix server or proxy by creating specially crafted JavaScript preprocessing or script items. This can lead to a denial of service condition where the server or proxy becomes unavailable.

Detection Guidance

This vulnerability requires authenticated administrator access to exploit. Monitor Zabbix server logs for crashes or unusual JavaScript preprocessing/script item errors. Check for items with suspicious JavaScript code in the Zabbix frontend.

Impact Analysis

If exploited, this vulnerability could cause your Zabbix monitoring system to crash, disrupting visibility into your infrastructure and potentially leading to unmonitored outages or performance issues.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR or HIPAA by enabling a denial of service attack against Zabbix server or proxy, which may disrupt monitoring and logging systems critical for maintaining data integrity and availability under these regulations.

Mitigation Strategies

Apply the latest security patches from Zabbix to address the JavaScript preprocessing/script item vulnerability. Restrict administrative access to trusted users only and monitor for unusual script executions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-23938. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart