HIGH
Prototype pollution leading to stored XSS
Published Aug 18, 2026
8.5
HIGHCVSS 4.0
EPSS 0.18%
Description
Prototype pollution vulnerability in searchParamsToObject() is leading to a persistent XSS in Maps. URL parameter processing was not filtering dangerous properties like __proto__, combined with jQuery's unsafe element creation that traversed the prototype chain.
Affected products
-
- Version 6.0.44StatusaffectedConstraints<=6.0.45
- Version 7.0.22StatusaffectedConstraints<=7.0.24
- Version 7.4.6StatusaffectedConstraints<=7.4.8
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Update the affected components to their respective fixed versions.
Weaknesses (1)
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-60734 Advisory
- https://support.zabbix.com/browse/ZBX-28068 Vendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-60734 | Advisory | |
| https://support.zabbix.com/browse/ZBX-28068 | Vendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Zabbix
Published Aug 18, 2026
Updated Aug 19, 2026
Reserved Jan 19, 2026
Link CVE-2026-23929
CISA Vulnrichment
Updated Aug 18, 2026
ENISA EUVD
EUVD-2026-60734 Assigner Zabbix
Published Aug 18, 2026
Updated Aug 19, 2026
Exploited since n/a
Link EUVD-2026-60734