Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.5

CVE-2026-23929: Zabbix allows crafted URL to run unwanted code

CVE-2026-23929 · published 1 month ago
Summary

Zabbix converts URL parameters into objects without blocking special property names such as __proto__. An attacker can supply a malicious URL that changes how pages are built, causing unwanted code to run every time a map is viewed. Update Zabbix to the latest version or apply the vendor's patch to stop this behavior.

What to do
  • Update zabbix zabbix to version 6.0.46.
Affected software
Ecosystem VendorProductAffected versions
Ubuntu:Pro:22.04:LTS canonical zabbix All versions
Ubuntu:26.04:LTS canonical zabbix All versions
– zabbix zabbix >= 6.0.0, < 6.0.46
>= 7.0.0, < 7.0.25
>= 7.4.0, < 7.4.9
<= 6.0.45
Fix: upgrade to 6.0.46
cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:*
Ubuntu:Pro:14.04:LTS canonical zabbix All versions
Ubuntu:Pro:16.04:LTS canonical zabbix All versions
Ubuntu:Pro:18.04:LTS canonical zabbix All versions
Ubuntu:Pro:20.04:LTS canonical zabbix All versions
Debian:11 debian zabbix All versions
Debian:12 debian zabbix All versions
Debian:13 debian zabbix All versions
Original advisory text
Prototype pollution vulnerability in searchParamsToObject() is leading to a persistent XSS in Maps. URL parameter processing was not filtering dangerous properties like __proto__, combined with jQu...
Prototype pollution vulnerability in searchParamsToObject() is leading to a persistent XSS in Maps. URL parameter processing was not filtering dangerous properties like __proto__, combined with jQuery's unsafe element creation that traversed the prototype chain.
Severity
8.5 High
CVSS 4.0: 9.4 (OSV)
Exploitation
EPSS <1%
Type
CWE-1321Prototype Pollution
Timeline
Published18 Aug 2026
Updated27 Sep 2026
First seen18 Aug 2026
Track software like this
Free during beta