CVE-2026-23929
Zabbix
Prototype pollution vulnerability in searchParamsToObject() is leading to a persistent XSS in Maps. URL parameter processing was not filtering dangerous properties like __proto__, combined with jQuery's unsafe element creation that traversed the prototype chain.
- CVSS
- 8.5
- EPSS
- 0.30% 21.7% percentile
- CISA KEV
- Not listed
- Published
- 2026.08.18