CVE-2026-23926

HIGH

Zabbix 7.0.0 to 7.4.7 - Host Navigator Tooltip Stored Cross-Site Scripting

Title source: manual
STIX 2.1

Description

An authenticated (non-super) administrator can create a maintenance period with a JavaScript payload that is executed by any user that opens tooltip for that maintenance period in the Host navigator widget. This can allow the attacker to perform unauthorized actions depending on which user opens the tooltip.

References (1)

Core 1

Scores

CVSS v4 7.3
EPSS 0.0029
EPSS Percentile 20.0%
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-79
Status published
Products (2)
Zabbix/Zabbix 7.0.0 - 7.0.23
Zabbix/Zabbix 7.4.0 - 7.4.7
Published May 06, 2026
Tracked Since May 06, 2026