CVE-2026-23935

A Zabbix administrator is able to read out of bounds memory by utilizing a flaw in script item/preprocessing (JavaScript) HttpRequest logic, leading to potential confidentiality loss.

Credits

Zabbix wants to thank Aikido Security for submitting this report on the HackerOne bug bounty platform.

References