Information disclosure in Zabbix - CVE-2026-59782
Published: October 5, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper isolation of heap data in the JavaScript preprocessing (Duktape) engine when defining malicious preprocessing rules. A remote privileged user can define malicious preprocessing rules to disclose sensitive information.
The disclosed heap data may originate from other running preprocessors.
Affected software
Fedora
zabbix6.0
zabbix
zabbix7.0
How to mitigate CVE-2026-59782
zabbix6.0 - update to 6.0.48-1.el8
zabbix - update to 6.0.48-1.el9
zabbix7.0 - addressed in versions 7.0.31-1.el8, 7.0.31-1.el9, 7.0.31-1.el10_2, 7.0.31-1.el10_3, 7.0.31-1.el10_4