Description
An authenticated administrator is able to crash Zabbix server or proxy by creating specifically crafted preprocessing/script item JavaScript scripts, leading to potential denial of service.
Published: 2026-08-18
Score: 2.1 Low
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An authenticated Zabbix administrator can cause the server or proxy to crash by creating specially crafted JavaScript scripts in preprocessing or script items. The flaw enables an attacker privileged with administrative rights to terminate the monitoring platform, disrupting service availability. The weakness is classified as CWE-248, indicating execution of unsafe fallback code that leads to instability.

Affected Systems

Zabbix servers and proxies that allow administrators to configure preprocessing or script items. No specific version details are provided, so any installation with the ability to add JavaScript scripts is potentially affected.

Risk and Exploitability

With a CVSS score of 2.1 the vulnerability is considered low severity. EPSS is not available and the issue is not listed in CISA KEV, reducing the likelihood of widespread exploitation. The attack requires prior administrative authentication and the creation of malicious scripts, so it is a local privilege escalation path rather than a remote exploit. Overall, the risk is moderate in environments where administrator accounts are not tightly controlled.

Generated by OpenCVE AI on August 18, 2026 at 14:03 UTC.

Remediation

Vendor Solution

Update the affected components to their respective fixed versions.


OpenCVE Recommended Actions

  • Update Zabbix server or proxy to the fixed version released by the vendor.
  • Restrict the creation and modification of preprocessing or script item JavaScript to trusted administrators only.
  • Disable or review custom JavaScript scripts until the update is applied to prevent accidental service crashes.

Generated by OpenCVE AI on August 18, 2026 at 14:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Zabbix
Zabbix zabbix
Vendors & Products Zabbix
Zabbix zabbix

Tue, 18 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
Description An authenticated administrator is able to crash Zabbix server or proxy by creating specifically crafted preprocessing/script item JavaScript scripts, leading to potential denial of service.
Title Server DoS via JavaScript preprocessing or script items
Weaknesses CWE-248
References
Metrics cvssV4_0

{'score': 2.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Zabbix

Published:

Updated: 2026-08-18T13:34:38.081Z

Reserved: 2026-01-19T14:03:13.686Z

Link: CVE-2026-23938

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T13:17:22.103

Modified: 2026-08-18T14:17:01.790

Link: CVE-2026-23938

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T14:15:07Z

Weaknesses