Information disclosure in Zabbix - CVE-2026-59782

 

Information disclosure in Zabbix - CVE-2026-59782

Published: October 5, 2026


Vulnerability identifier: #VU153280
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-59782
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper isolation of heap data in the JavaScript preprocessing (Duktape) engine when defining malicious preprocessing rules. A remote privileged user can define malicious preprocessing rules to disclose sensitive information.

The disclosed heap data may originate from other running preprocessors.


Affected software

Zabbix
Fedora
zabbix6.0
zabbix
zabbix7.0

How to mitigate CVE-2026-59782

Install security update from vendor's website.

Zabbix - addressed in versions 6.0.48, 7.0.29, 7.4.13
zabbix6.0 - update to 6.0.48-1.el8
zabbix - update to 6.0.48-1.el9
zabbix7.0 - addressed in versions 7.0.31-1.el8, 7.0.31-1.el9, 7.0.31-1.el10_2, 7.0.31-1.el10_3, 7.0.31-1.el10_4

External References

Related Security Bulletins