Description
A Zabbix administrator is able to read out of bounds memory by utilizing a flaw in script item/preprocessing (JavaScript) HttpRequest logic, leading to potential confidentiality loss.
Published: 2026-08-18
Score: 6.8 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A use‑after‑free flaw in Zabbix’s script item/preprocessing logic allows a Zabbix administrator to trigger a read of memory beyond the bounds of an HTTP request buffer. The vulnerability is triggered when a preprocessor script includes a JavaScript HttpRequest, and an attacker can cause the server to emit a memory access that leaks sensitive data, leading to potential confidentiality loss.

Affected Systems

Zabbix – the description does not specify affected component versions. Any installation that relies on the vulnerable script item/preprocessing API is potentially impacted.

Risk and Exploitability

The CVSS score of 6.8 indicates a moderate severity, and the vulnerability is not listed in the KEV catalog. The EPSS score is not available, so the current likelihood of exploitation is unknown, but the flaw requires administrative privileges or the ability to add or alter preprocessor scripts. If these conditions are satisfied, an attacker can read arbitrary data from the Zabbix process, compromising confidentiality. The exploit path is local to the Zabbix database server and does not provide elevated privilege escalation beyond the preprocessor context.

Generated by OpenCVE AI on August 18, 2026 at 13:50 UTC.

Remediation

Vendor Solution

Update the affected components to their respective fixed versions.


OpenCVE Recommended Actions

  • Upgrade Zabbix to the latest release that contains the fix for the use‑after‑free flaw
  • Restrict user privileges so that only trusted administrators can create or modify preprocessor scripts that use JavaScript HttpRequest calls
  • Audit existing preprocessor scripts for unexpected HttpRequest usage and remove any that are not required

Generated by OpenCVE AI on August 18, 2026 at 13:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Zabbix
Zabbix zabbix
Vendors & Products Zabbix
Zabbix zabbix

Tue, 18 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
Description A Zabbix administrator is able to read out of bounds memory by utilizing a flaw in script item/preprocessing (JavaScript) HttpRequest logic, leading to potential confidentiality loss.
Title Use-after-free read in script item/preprocessing HttpRequest body
Weaknesses CWE-125
References
Metrics cvssV4_0

{'score': 6.8, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Zabbix

Published:

Updated: 2026-08-18T13:34:59.670Z

Reserved: 2026-01-19T14:03:13.686Z

Link: CVE-2026-23935

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T13:17:21.843

Modified: 2026-08-18T14:17:01.557

Link: CVE-2026-23935

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T14:15:07Z

Weaknesses