Input validation error in Zabbix - CVE-2026-59781

 

Input validation error in Zabbix - CVE-2026-59781

Published: August 18, 2026


Vulnerability identifier: #VU144182
CSH Severity: Medium
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-59781
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to execute arbitrary code.

The vulnerability exists due to improper validation of custom installation directories in the Zabbix Agent installer on Windows when installing the agent into a custom directory with unsafe permissions. A local user can place a malicious DLL in the insecure installation directory to execute arbitrary code.

The issue arises because Windows may load the malicious DLL due to the DLL search order, and user interaction is required during installation.


Affected software

Zabbix

How to mitigate CVE-2026-59781

Install security update from vendor's website.

Zabbix - addressed in versions 6.0.48, 7.0.29, 7.4.13

External References

Related Security Bulletins