SB2026100544 - Multiple vulnerabilities in Zabbix



SB2026100544 - Multiple vulnerabilities in Zabbix

Published: October 5, 2026

Security Bulletin ID SB2026100544
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 5
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 20% Low 80%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 5 vulnerabilities.


1) Improper Neutralization of Special Elements in Output Used by a Downstream Component (CVE-ID: CVE-2026-59787)

CWE-ID: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to modify records for another host.

The vulnerability exists due to improper neutralization of the ZBXTRAP record delimiter in the zabbix_trap_receiver.pl Perl SNMP trap receiver script when processing crafted SNMP trap payloads. A remote user can send a crafted SNMP trap payload to inject a record targeting another host to modify records for another host.


2) Improper Authentication (CVE-ID: CVE-2026-59786)

CWE-ID: CWE-287 - Improper Authentication

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to alter host availability status.

The vulnerability exists due to improper authentication in active agent heartbeat handling by Zabbix Server and Proxy when processing crafted heartbeat packets on the Zabbix trapper port. A remote attacker can send a crafted heartbeat packet to alter host availability status.

The issue affects deployments configured to use PSK or certificate authentication.


3) Information disclosure (CVE-ID: CVE-2026-59785)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 5.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose stored IPMI and PSK credentials.

The vulnerability exists due to improper access control in Frontend host search when filtering by fields that are not displayed. A remote user can send crafted search queries to disclose stored IPMI and PSK credentials.

Exploitation requires host read access.


4) Input validation error (CVE-ID: CVE-2026-59783)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to improper handling of null byte input in Zabbix Server and Proxy binary items when processing malicious data sent through trapper access. A remote user can send malicious binary-item data containing null bytes to cause a denial of service.

Only deployments using MySQL or MariaDB as the Zabbix database are affected.


5) Information disclosure (CVE-ID: CVE-2026-59782)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper isolation of heap data in the JavaScript preprocessing (Duktape) engine when defining malicious preprocessing rules. A remote privileged user can define malicious preprocessing rules to disclose sensitive information.

The disclosed heap data may originate from other running preprocessors.


Remediation

Install update from vendor's website.