SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-23935

MEDIUM · CVSS 6.8 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-08-18 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A vulnerability in the Java implementation of Zabbix allows an administrator to exploit a flaw in the script item/preprocessing (JavaScript) HttpRequest logic, resulting in out-of-bounds memory access. This could lead to potential confidentiality loss by exposing sensitive information. Organizations using Zabbix with Java should prioritize addressing this issue to mitigate risks associated with unauthorized data access.

CVE
CVE-2026-23935
Severity
MEDIUM
CVSS
6.8
EPSS
0.18%
Java

Original NVD Description

A Zabbix administrator is able to read out of bounds memory by utilizing a flaw in script item/preprocessing (JavaScript) HttpRequest logic, leading to potential confidentiality loss.