Improper Authentication in Zabbix - CVE-2026-59786
Published: October 5, 2026
Vulnerability details
The vulnerability allows a remote attacker to alter host availability status.
The vulnerability exists due to improper authentication in active agent heartbeat handling by Zabbix Server and Proxy when processing crafted heartbeat packets on the Zabbix trapper port. A remote attacker can send a crafted heartbeat packet to alter host availability status.
The issue affects deployments configured to use PSK or certificate authentication.
Affected software
Fedora
zabbix7.0
How to mitigate CVE-2026-59786
zabbix7.0 - addressed in versions 7.0.31-1.el8, 7.0.31-1.el9, 7.0.31-1.el10_2, 7.0.31-1.el10_3, 7.0.31-1.el10_4