CVE-2026-23938: Server DoS via JavaScript preprocessing or script items
Published Aug 18, 2026
·Updated
An authenticated administrator is able to crash Zabbix server or proxy by creating specifically crafted preprocessing/script item JavaScript scripts, leading to potential denial of service.
Affected Software
5 affected components
Zabbix Zabbix server
Zabbix Zabbix Proxy
Zabbix Zabbix>=6.0.0<6.0.47
Zabbix Zabbix>=7.0.0<7.0.27
Zabbix Zabbix>=7.4.0<7.4.11
Event History
Aug 18, 2026
CVE Published
via MITRE·12:20 PM
Data Sourced
via MITRE·12:20 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
Exploitation requires authenticated administrator access. The issue affects Zabbix server and Zabbix Proxy deployments where an administrator can create crafted JavaScript preprocessing or script-item code.
2
What is the expected impact of successful exploitation?
A successful exploit can crash the Zabbix server or proxy, causing denial of service. The provided information does not indicate data exposure, privilege escalation, or code execution beyond the ability to create the crafted scripts.