Security Advisory

CVE-2026-23929

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-18 12:16:15
Last updated 2026-08-19 03:55:58
Assigner Zabbix
CVSS score 8.5
State PUBLISHED

Description

Prototype pollution vulnerability in searchParamsToObject() is leading to a persistent XSS in Maps. URL parameter processing was not filtering dangerous properties like __proto__, combined with jQuery's unsafe element creation that traversed the prototype chain.