Your message dated Thu, 20 Aug 2026 09:04:41 +0000
with message-id <[email protected]>
and subject line Bug#1137209: fixed in zabbix 1:7.0.27+dfsg-1
has caused the Debian Bug report #1137209,
regarding zabbix: CVE-2026-23926 CVE-2026-23927 CVE-2026-23928
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1137209: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1137209
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: zabbix
Version: 1:7.0.22+dfsg-1.1
Severity: grave
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi,
The following vulnerabilities were published for zabbix.
Choosed RC level severity as this should be fixed for forky.
CVE-2026-23926[0]:
| An authenticated (non-super) administrator can create a maintenance
| period with a JavaScript payload that is executed by any user that
| opens tooltip for that maintenance period in the Host navigator
| widget. This can allow the attacker to perform unauthorized actions
| depending on which user opens the tooltip.
CVE-2026-23927[1]:
| A user able to connect to Agent 2 can inject an Oracle TNS
| connection string via the 'service' parameter. This can lead to
| Agent 2 connecting to an attacker-controlled server and leaking
| Oracle database credentials if they are saved in a named session.
CVE-2026-23928[2]:
| The Item history widget (in Zabbix 7.0+) or the Plain text widget
| (in Zabbix 6.0) can execute injected JavaScript when HTML display is
| enabled. This can allow an attacker to perform unauthorized actions
| depending on which user opens a dashboard containing these widgets.
| The malicious JavaScript would have to come from a monitored host
| controlled by the attacker. Note: the Item history widget is a
| replacement for the Plain text widget since Zabbix 7.0.
If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-23926
https://www.cve.org/CVERecord?id=CVE-2026-23926
[1] https://security-tracker.debian.org/tracker/CVE-2026-23927
https://www.cve.org/CVERecord?id=CVE-2026-23927
[2] https://security-tracker.debian.org/tracker/CVE-2026-23928
https://www.cve.org/CVERecord?id=CVE-2026-23928
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: zabbix
Source-Version: 1:7.0.27+dfsg-1
Done: Dmitry Smirnov <[email protected]>
We believe that the bug you reported is fixed in the latest version of
zabbix, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Dmitry Smirnov <[email protected]> (supplier of updated zabbix package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Thu, 20 Aug 2026 13:22:21 +1000
Source: zabbix
Architecture: source
Version: 1:7.0.27+dfsg-1
Distribution: unstable
Urgency: high
Maintainer: Dmitry Smirnov <[email protected]>
Changed-By: Dmitry Smirnov <[email protected]>
Closes: 1132226 1137209
Changes:
zabbix (1:7.0.27+dfsg-1) unstable; urgency=high
.
* New upstream release. (Closes: #1132226, #1137209)
+ CVE-2026-23924 (fixed in 7.0.23)
+ CVE-2026-23926 (fixed in 7.0.24)
+ CVE-2026-23927 (fixed in 7.0.24)
+ CVE-2026-23928 (fixed in 7.0.24)
* Use vendored "github.com/go-ldap/ldap" due to FTBFS.
* Build-Depends:
+ golang-gopkg-asn1-ber.v1-dev
Checksums-Sha1:
7e4e19ac58368b330112b5596aa254f160b897d0 4199 zabbix_7.0.27+dfsg-1.dsc
548cbf04988c991a16bc75b5038240ff9a17f9d8 13682536
zabbix_7.0.27+dfsg.orig-templates.tar.xz
62d400e5b9a220dbe954e0871d767ab1c83f6bcc 927796
zabbix_7.0.27+dfsg.orig-vendor.tar.xz
6297baf11a9cbad81a60c4a296ecfcc42ddc9421 22820664
zabbix_7.0.27+dfsg.orig.tar.xz
9926306f71930236316ee5e13f47b878c82a4ae1 144972
zabbix_7.0.27+dfsg-1.debian.tar.xz
5e953b123526a3fde20435b31ff8b83f95af1e7e 20899
zabbix_7.0.27+dfsg-1_amd64.buildinfo
Checksums-Sha256:
4f70f051ee5e99ff37aa172c0af775494bcc4ce663357fcc69e6daae2b307086 4199
zabbix_7.0.27+dfsg-1.dsc
5571aec802cb86b1732e57178156222abc55b528c15cf65f94d9cd0fef60fc51 13682536
zabbix_7.0.27+dfsg.orig-templates.tar.xz
f479d0fd2b86e673bda22c3103b1f52c68011a0c346e46e76a0fa86b0f0c2451 927796
zabbix_7.0.27+dfsg.orig-vendor.tar.xz
d84b463722da9976e6992caa89b15ec2669a48993d5a7fb743eab3dd393795d4 22820664
zabbix_7.0.27+dfsg.orig.tar.xz
fdccc784abe7ace3c1babb880d3ebdb2e86ffce615d9af8dc29236fa8d5d1984 144972
zabbix_7.0.27+dfsg-1.debian.tar.xz
a49a6611b94a4fbf19cf1ee92d8161c7fa6d1522a9ec163035bb45f188e85f31 20899
zabbix_7.0.27+dfsg-1_amd64.buildinfo
Files:
cee52da363bd3486f8e966512380d6e1 4199 net optional zabbix_7.0.27+dfsg-1.dsc
2bc23fc75ed1be4648502322acba4a03 13682536 net optional
zabbix_7.0.27+dfsg.orig-templates.tar.xz
e22252d8d9e5d455b83c2ec38416ff14 927796 net optional
zabbix_7.0.27+dfsg.orig-vendor.tar.xz
f805f6dee97a63ea2b70dcf850530fe2 22820664 net optional
zabbix_7.0.27+dfsg.orig.tar.xz
8fdd2ca1e9162cd5d2d0a55caa38981b 144972 net optional
zabbix_7.0.27+dfsg-1.debian.tar.xz
44994d3a92492172174eeff63cde666e 20899 net optional
zabbix_7.0.27+dfsg-1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEULx8+TnSDCcqawZWUra72VOWjRsFAmqGtBUACgkQUra72VOW
jRvslhAAisEoBPBGWqMV4ycaY7xlAWm8A/SxIZkTp1tLfkkKtYn1VlrCIsgL7dkb
R6qyW1WC2SscTYV8iXoWhR6C7RUSroCacgcM4zdYN6vfRhpM+ZmWxpQc4V6sWy98
Zye4939PcNTmxCUul3tUfmold5rUW+bVAnEGCNhrA23eKa2sYBw8qPa0z+2mJF6r
5D9xbfxBWzwtE4tj/9EE+5Mlik4IgoIVroAMig5iy2LkBH2gLrclhl6hIwvQXptW
Mf2PlIh44MrOdqb2etN06OfevcjDrire4gjU+2zGVJns/ZgrGztchlXeL+dUy8Wh
jB0CQI1nNt5K4w3eNhjWycCU0hGzXWEAmEZp/72vMr1enfgh5QbOUZgtEWKl5+Fv
yon0D2/b2nelXqMiBHuD7C8e0fvWdXpDVCpMHR8TsrmcS5pN9CC44OtR7TborHWw
0AnfEp9aXBLCQRwRD8b7LRIqfveDv/Ii3wxcPNu3izi9LHKjqqqVmDCms1WfFuGe
o/2HEQ0HIMPxSCwt8gSr7B4qL40x1ZP8DYSVk9k+p6M7aj0fc4bEzPiGEgypB0SJ
dzbM4aZYbNrKA3bJqQ5A4hosDQeig1fN58UfHYmh4SWK0Bx338M3iSwQTDnB9vM5
jP93q6ggTdfW5//toAoTWZE4nQWHJl0PTlsgZfBrZRBLywNJWa0=
=ow+H
-----END PGP SIGNATURE-----
pgp7I_3gZzeCa.pgp
Description: PGP signature
--- End Message ---