OAuth Form Vulnerability in Zabbix Affects Super Admin Permissions
CVE-2026-59788
5.6MEDIUM
What is CVE-2026-59788?
A security flaw in Zabbix's email media type OAuth form allows the Authorization endpoint value to be passed to the window.open() function without proper validation of the URL scheme. This vulnerability can enable a crafted media type configuration, delivered as an import file, to execute arbitrary JavaScript within the browser as the Super Admin who grants consent. This presents a significant risk by potentially allowing unauthorized actions or compromising sensitive admin functionalities.
Affected Version(s)
Zabbix 7.4.0 <= 7.4.11
