CVE-2026-23928: Stored XSS vulnerability in the Item history/Plain text widget
The Item history widget (in Zabbix 7.0+) or the Plain text widget (in Zabbix 6.0) can execute injected JavaScript when HTML display is enabled. This can allow an attacker to perform unauthorized actions depending on which user opens a dashboard containing these widgets. The malicious JavaScript would have to come from a monitored host controlled by the attacker. Note: the Item history widget is a replacement for the Plain text widget since Zabbix 7.0.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-23928?
CVE-2026-23928 has been classified as a high-severity stored XSS vulnerability.
How do I fix CVE-2026-23928?
To mitigate CVE-2026-23928, update your Zabbix installation to the latest version where the vulnerability has been patched.
When was CVE-2026-23928 reported?
CVE-2026-23928 was reported as a vulnerability in Zabbix versions 6.0 and higher.
Who is affected by CVE-2026-23928?
Users of Zabbix 6.0 and above that have HTML display enabled in the Item history or Plain text widget are affected by CVE-2026-23928.
What type of attacks can CVE-2026-23928 enable?
CVE-2026-23928 can enable attackers to execute unauthorized actions depending on the privileges of the user who opens the affected widget.