Improper Authentication in Zabbix - CVE-2026-59786

 

Improper Authentication in Zabbix - CVE-2026-59786

Published: October 5, 2026


Vulnerability identifier: #VU153277
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-59786
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to alter host availability status.

The vulnerability exists due to improper authentication in active agent heartbeat handling by Zabbix Server and Proxy when processing crafted heartbeat packets on the Zabbix trapper port. A remote attacker can send a crafted heartbeat packet to alter host availability status.

The issue affects deployments configured to use PSK or certificate authentication.


Affected software

Zabbix
Fedora
zabbix7.0

How to mitigate CVE-2026-59786

Install security update from vendor's website.

Zabbix - addressed in versions 7.0.29, 7.4.13
zabbix7.0 - addressed in versions 7.0.31-1.el8, 7.0.31-1.el9, 7.0.31-1.el10_2, 7.0.31-1.el10_3, 7.0.31-1.el10_4

External References

Related Security Bulletins