SB2026081857 - Input validation error in Zabbix



SB2026081857 - Input validation error in Zabbix

Published: August 18, 2026

Security Bulletin ID SB2026081857
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Code execution

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Input validation error (CVE-ID: CVE-2026-59781)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to execute arbitrary code.

The vulnerability exists due to improper validation of custom installation directories in the Zabbix Agent installer on Windows when installing the agent into a custom directory with unsafe permissions. A local user can place a malicious DLL in the insecure installation directory to execute arbitrary code.

The issue arises because Windows may load the malicious DLL due to the DLL search order, and user interaction is required during installation.


Remediation

Install update from vendor's website.