SB2026081857 - Input validation error in Zabbix
Published: August 18, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Input validation error (CVE-ID: CVE-2026-59781)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to execute arbitrary code.
The vulnerability exists due to improper validation of custom installation directories in the Zabbix Agent installer on Windows when installing the agent into a custom directory with unsafe permissions. A local user can place a malicious DLL in the insecure installation directory to execute arbitrary code.
The issue arises because Windows may load the malicious DLL due to the DLL search order, and user interaction is required during installation.
Remediation
Install update from vendor's website.