nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-23920 CVE-2026-23920
HIGH
Host and event action script regex validation can be bypassed in certain situations, leading to potential command injection
Record summary
CVE-2026-23920 has a selected CVSS score of 7.7 (high).
Description
Host and event action script input is validated with a regex (set by the administrator), but the validation runs in multiline mode. If ^ and $ anchors are used in user input validation, an injected newline lets authenticated users bypass the check and inject shell commands.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 25, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
ZabbixBrowse Zabbix / ZabbixDefault status: unknown | CVE List | 7.0.0 to ≤ 7.0.21 | affected |
| 7.2.0 to ≤ 7.2.14 | affected | ||
| 7.4.0 to ≤ 7.4.5 | affected |
References
2support.zabbix.com
https://support.zabbix.com/browse/ZBX-27639