Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.5
CVE-2026-23929: Zabbix allows crafted URL to run unwanted code
CVE-2026-23929 · published 1 month ago
Summary
Zabbix converts URL parameters into objects without blocking special property names such as __proto__. An attacker can supply a malicious URL that changes how pages are built, causing unwanted code to run every time a map is viewed. Update Zabbix to the latest version or apply the vendor's patch to stop this behavior.
What to do
- Update zabbix zabbix to version 6.0.46.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Ubuntu:Pro:22.04:LTS | canonical | zabbix | All versions |
| Ubuntu:26.04:LTS | canonical | zabbix | All versions |
| – | zabbix | zabbix |
>= 6.0.0, < 6.0.46 >= 7.0.0, < 7.0.25 >= 7.4.0, < 7.4.9 <= 6.0.45 Fix: upgrade to 6.0.46
cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:* |
| Ubuntu:Pro:14.04:LTS | canonical | zabbix | All versions |
| Ubuntu:Pro:16.04:LTS | canonical | zabbix | All versions |
| Ubuntu:Pro:18.04:LTS | canonical | zabbix | All versions |
| Ubuntu:Pro:20.04:LTS | canonical | zabbix | All versions |
| Debian:11 | debian | zabbix | All versions |
| Debian:12 | debian | zabbix | All versions |
| Debian:13 | debian | zabbix | All versions |
Original advisory text
Prototype pollution vulnerability in searchParamsToObject() is leading to a persistent XSS in Maps. URL parameter processing was not filtering dangerous properties like __proto__, combined with jQu...
Prototype pollution vulnerability in searchParamsToObject() is leading to a persistent XSS in Maps. URL parameter processing was not filtering dangerous properties like __proto__, combined with jQuery's unsafe element creation that traversed the prototype chain.
References
- https://support.zabbix.com/browse/ZBX-28068 Vendor Advisory
- https://security-tracker.debian.org/tracker/CVE-2026-23929 Vendor Advisory
- https://ubuntu.com/security/CVE-2026-23929 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-23929 Third Party Advisory
Severity
8.5
High
CVSS 4.0: 9.4 (OSV)
Exploitation
EPSS <1%
Type
CWE-1321Prototype Pollution
Timeline
Published18 Aug 2026
Updated27 Sep 2026
First seen18 Aug 2026
Sources
UBUNTU-CVE-2026-23929 · OSV
CVE-2026-23929 · NVD
CVE-2026-23929 · MITRE
DEBIAN-CVE-2026-23929 · OSV
Track software like this
Free during beta