logo

Zabbix Flaws Allow Monitored Hosts to Hijack Admin Dashboards

ID: 7f402c18-1192-5193-81b6-8f8228d4dd70

STIX ID: report--7f402c18-1192-5193-81b6-8f8228d4dd70

Feed Name: securityonline.info

Threat Score
65/100

Date Published: 2026-05-08

Date Updated: 2026-05-08

Author: Ddos

...
...

Zabbix released security patches for three vulnerabilities: two high-severity stored XSS issues in the Frontend (Host Navigator and Item History widgets) enabling execution of attacker-supplied JavaScript by administrators, and a medium-severity injection flaw in Agent 2's Oracle plugin that can redirect connections to attacker-controlled servers and leak Oracle credentials; fixed versions and mitigations are listed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.