CVE-2026-23929

Summary

Prototype pollution vulnerability in searchParamsToObject() is leading to a persistent XSS in Maps. URL parameter processing was not filtering dangerous properties like proto, combined with jQuery's unsafe element creation that traversed the prototype chain.

Affected Software

VendorProductVersion RangeStatus
ZabbixZabbix6.0.44 <= 6.0.45affected
ZabbixZabbix7.0.22 <= 7.0.24affected
ZabbixZabbix7.4.6 <= 7.4.8affected

Weaknesses

  • CWE-1321: CWE-1321: Improperly Controlled Modification of Object Prototype Attributes ("Prototype Pollution")

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References