Prototype Pollution Vulnerability in Maps by Zabbix
CVE-2026-23929

8.5HIGH

Key Information:

Vendor

Zabbix

Status
Vendor
CVE Published:
18 August 2026

What is CVE-2026-23929?

A prototype pollution vulnerability in the Maps component of Zabbix allows for the manipulation of object properties via the searchParamsToObject() function. This vulnerability results in a persistent Cross-Site Scripting (XSS) attack, as it does not adequately filter harmful properties, such as 'proto'. Coupled with jQuery's insecure element creation methods that traverse the prototype chain, this issue could potentially lead to severe security breaches, allowing attackers to inject malicious scripts into the application.

Affected Version(s)

Zabbix 6.0.44 <= 6.0.45

Zabbix 7.0.22 <= 7.0.24

Zabbix 7.4.6 <= 7.4.8

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Zabbix wants to thank Perce, 6o_o9 and Nassim BETTACH @Shenron for submitting this report on the HackerOne bug bounty platform.
.