CVE Tools

CVE-2026-23920

Host and event action script regex validation can be bypassed in certain situations, leading to potential command injection

Published: Mar 24, 2026Updated: Sep 10, 2026 Sources: CVE List NVD BDUCWE-78

Description

Host and event action script input is validated with a regex (set by the administrator), but the validation runs in multiline mode. If ^ and $ anchors are used in user input validation, an injected newline lets authenticated users bypass the check and inject shell commands.

In plain language

AI Worth attention

Zabbix installations not yet updated to 7.0.22 should be reviewed, because a logged-in user may be able to run unwanted commands on the server.

Executive summary

Authenticated command injection in Zabbix host and event action scripts: multiline regex validation permits newline-based bypasses when administrators use ^ and $ anchors.

If affected, business impact
Server command executionMonitoring system takeoverService disruptionSensitive data exposure

What to do now

  1. Check whether you run Zabbix and whether host or event actions use script input validation.
  2. Upgrade Zabbix to 7.0.22.
  3. If upgrading is delayed, replace ^ and $ in affected validation rules with \A and \z.
  4. Review who can edit or trigger action scripts and remove unnecessary access.
Patch / advisory Usually a quick update

CVSS Vector Breakdown

AV:NAC:LPR:LUI:NS:UC:HI:HA:H
Exploitability
AV:NAttack Vector
Network
AC:LAttack Complexity
Low
PR:LPrivileges Required
Low
UI:NUser Interaction
None
Scope
S:UScope
Unchanged
Impact
C:HConfidentiality
High
I:HIntegrity
High
A:HAvailability
High

Weaknesses

Affected Products

and 1 more affected products View all →

Exploitability

Official Patch Available
Workaround Available

Attack Graph

Products CVE Techniques Tactics

Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.

MITRE ATT&CK

1 technique
Execution
View detailed technique mapping

References

and 2 more references View all →

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2026-23920 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store