SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-23938

LOW · CVSS 2.1 EPSS 0.30%

Source: NVD + CISA KEV + EPSS · Published 2026-08-18 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

An authenticated administrator can exploit a vulnerability in Java used by Zabbix by crafting malicious preprocessing or script item JavaScript scripts, which may result in a denial of service by crashing the Zabbix server or proxy. Organizations utilizing Zabbix for monitoring should prioritize this issue to prevent potential disruptions in service. Although the severity is rated low, the impact on availability could be significant in critical environments.

CVE
CVE-2026-23938
Severity
LOW
CVSS
2.1
EPSS
0.30%
Java

Original NVD Description

An authenticated administrator is able to crash Zabbix server or proxy by creating specifically crafted preprocessing/script item JavaScript scripts, leading to potential denial of service.