CVE-2026-23919

high

Description

For performance reasons Zabbix Server/Proxy reuses JavaScript (Duktape) contexts (used in script items, JavaScript reprocessing, Webhooks). This can lead to confidentiality loss where a regular (non-super) Zabbix administrator leaks data for hosts they do not have access to. A fix has been released that makes the built in Zabbix JavaScript objects read-only, but please be advised that usage of global JavaScript variables is not recommended because their content could be leaked. More information <a href='https://www.zabbix.com/documentation/7.4/en/manual/installation/known_issues#preprocessing-global-variables-are-unsafe'>in Zabbix documentation</a>.

References

https://support.zabbix.com/browse/ZBX-27638

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-14950

Details

Source: Mitre, NVD

Published: 2026-03-24

Updated: 2026-09-18

Risk Information

CVSS v2

Base Score: 7.3

Vector: CVSS2#AV:N/AC:L/Au:M/C:C/I:P/A:P

Severity: High

CVSS v3

Base Score: 6

Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L

Severity: Medium

CVSS v4

Base Score: 7.1

Vector: CVSS:4.0/AV:A/AC:L/AT:P/PR:H/UI:N/VC:H/VI:L/VA:L/SC:H/SI:L/SA:L

Severity: High

EPSS

EPSS: 0.00018