nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-23926 CVE-2026-23926
HIGH
Stored XSS vulnerability in Host navigator widget maintenance tooltip
Record summary
CVE-2026-23926 has a selected CVSS score of 7.3 (high).
Description
An authenticated (non-super) administrator can create a maintenance period with a JavaScript payload that is executed by any user that opens tooltip for that maintenance period in the Host navigator widget. This can allow the attacker to perform unauthorized actions depending on which user opens the tooltip.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated May 6, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
ZabbixBrowse Zabbix / ZabbixDefault status: unknown | CVE List | 7.0.0 to ≤ 7.0.23 | affected |
| 7.4.0 to ≤ 7.4.7 | affected |
References
2support.zabbix.com
https://support.zabbix.com/browse/ZBX-27758