CVE-2026-23938

Description

A flaw was found in Zabbix. An authenticated administrator can exploit this vulnerability by creating specially crafted JavaScript scripts within preprocessing or script items. This can lead to a denial of service (DoS) by crashing the Zabbix server or proxy.

Statement

Zabbix is not shipped in any Red Hat product. This flaw affects community packages in Fedora and EPEL only.

Mitigation

Restrict administrative access to trusted users only. Review and audit JavaScript preprocessing and script items configured on the Zabbix server.

Understanding the Weakness (CWE)

Availability

Technical Impact: DoS: Resource Consumption (CPU); DoS: Resource Consumption (Memory); DoS: Resource Consumption (Other)

When allocating resources without limits, an attacker could prevent other systems, applications, or processes from accessing the same type of resource. It can be easy for an attacker to consume many resources by rapidly making many requests or causing larger resources to be used than is needed.

Frequently Asked Questions

Want to get errata notifications? Sign up here.