What is CVE-2026-23935?
CVE-2026-23935 allows a Zabbix administrator to read out-of-bounds memory by exploiting a flaw in the script item/preprocessing (JavaScript) HttpRequest logic, leading to potential confidentiality loss. Zabbix administrators should apply security updates immediately to mitigate the risk.
Azərbaycanca: CVE-2026-23935, Zabbix-də script item/preprocessing (JavaScript) HttpRequest funksiyasında olan səhvə görə Zabbix administratoruna ayrılmış yaddaş sahəsindən kənar məlumatları oxumağa imkan verir. Bu, məxfi məlumatların potensial ifşasına səbəb ola bilər, Zabbix administratorlarının dərhal təhlükəsizlik yeniləmələrini tətbiq etmələri tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-125
FAQ2
Which function in Zabbix is affected by CVE-2026-23935?
CVE-2026-23935 occurs due to a flaw in the script item/preprocessing (JavaScript) HttpRequest function in Zabbix.
What security impact can exploiting this vulnerability have?
This flaw allows a Zabbix administrator to read out-of-bounds memory, which can lead to potential confidentiality loss.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.