OAuth Form Vulnerability in Zabbix Affects Super Admin Permissions
CVE-2026-59788

5.6MEDIUM

Key Information:

Vendor

Zabbix

Status
Vendor
CVE Published:
5 October 2026

What is CVE-2026-59788?

A security flaw in Zabbix's email media type OAuth form allows the Authorization endpoint value to be passed to the window.open() function without proper validation of the URL scheme. This vulnerability can enable a crafted media type configuration, delivered as an import file, to execute arbitrary JavaScript within the browser as the Super Admin who grants consent. This presents a significant risk by potentially allowing unauthorized actions or compromising sensitive admin functionalities.

Affected Version(s)

Zabbix 7.4.0 <= 7.4.11

References

CVSS V4

Score:
5.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.