Prototype Pollution Vulnerability in Maps by Zabbix
CVE-2026-23929
8.5HIGH
What is CVE-2026-23929?
A prototype pollution vulnerability in the Maps component of Zabbix allows for the manipulation of object properties via the searchParamsToObject() function. This vulnerability results in a persistent Cross-Site Scripting (XSS) attack, as it does not adequately filter harmful properties, such as 'proto'. Coupled with jQuery's insecure element creation methods that traverse the prototype chain, this issue could potentially lead to severe security breaches, allowing attackers to inject malicious scripts into the application.
Affected Version(s)
Zabbix 6.0.44 <= 6.0.45
Zabbix 7.0.22 <= 7.0.24
Zabbix 7.4.6 <= 7.4.8
References
CVSS V4
Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Zabbix wants to thank Perce, 6o_o9 and Nassim BETTACH @Shenron for submitting this report on the HackerOne bug bounty platform.
