CVE-2026-23926
HIGHZabbix 7.0.0 to 7.4.7 - Host Navigator Tooltip Stored Cross-Site Scripting
Title source: manualDescription
An authenticated (non-super) administrator can create a maintenance period with a JavaScript payload that is executed by any user that opens tooltip for that maintenance period in the Host navigator widget. This can allow the attacker to perform unauthorized actions depending on which user opens the tooltip.
References (1)
Core 1
Core References
Scores
CVSS v4
7.3
EPSS
0.0029
EPSS Percentile
20.0%
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-79
Status
published
Products (2)
Zabbix/Zabbix
7.0.0 - 7.0.23
Zabbix/Zabbix
7.4.0 - 7.4.7
Published
May 06, 2026
Tracked Since
May 06, 2026