An authenticated (non-super) administrator can create a maintenance period with a JavaScript payload that is executed by any user that opens tooltip for that maintenance period in the Host navigator widget. This can allow the attacker to perform unauthorized actions depending on which user opens the tooltip.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

Update the affected components to their respective fixed versions.


Workaround

Disable the Host navigator widget via Administration -> General -> Modules.

History

Wed, 06 May 2026 07:30:00 +0000

Type Values Removed Values Added
Description An authenticated (non-super) administrator can create a maintenance period with a JavaScript payload that is executed by any user that opens tooltip for that maintenance period in the Host navigator widget. This can allow the attacker to perform unauthorized actions depending on which user opens the tooltip.
Title Stored XSS vulnerability in Host navigator widget maintenance tooltip
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 7.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Zabbix

Published:

Updated: 2026-05-06T06:58:51.362Z

Reserved: 2026-01-19T14:02:54.327Z

Link: CVE-2026-23926

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-05-06T08:16:01.837

Modified: 2026-05-06T08:16:01.837

Link: CVE-2026-23926

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-06T08:30:25Z

Weaknesses