Новый пакет найденных в Zabbix уязвимостей и способы их устранения. Не забывайте обновляться.
———————————————-
CVE ID: CVE-2026-59782
CVSS score: 6.9 (Medium)
Affected components: Server, Proxy
Summary: JavaScript preprocessing memory disclosure
Description: The JavaScript preprocessing (Duktape) engine on Zabbix server has a vulnerability where a limited administrator is able to read raw heap data potentially resulting in leaked data from other running preprocessors not available to said administrator.
Known attack vectors: An attacker with limited administrator access to the Zabbix Frontend can define malicious preprocessing rules.
Affected and fix version/s:
Affected: 6.0.0 - 6.0.47 > Fixed: 6.0.48
Affected: 7.0.0 - 7.0.28 > Fixed: 7.0.29
Affected: 7.4.0 - 7.4.12 > Fixed: 7.4.13
Mitigation: Update the affected components to their respective fixed versions.
Workarounds: None
———————————————-
CVE ID: CVE-2026-59786
CVSS score: 6.9 (Medium)
Affected components: Server, Proxy
Summary: Active agent heartbeat missing TLS check
Description: Zabbix Server and Proxy accept the active agent heartbeat message regardless of the configured PSK or certificate authentication. This means someone with access to the Zabbix trapper port can report an arbitrary host using an active agent as available, resulting in a loss of integrity.
Known attack vectors: An attacker with network access to the trapper port sending crafted heartbeat packets.
Affected and fix version/s:
Affected: 7.0.0 - 7.0.28 > Fixed: 7.0.29
Affected: 7.4.0 - 7.4.12 > Fixed: 7.4.13
Mitigation: Update the affected components to their respective fixed versions.
Workarounds: None
———————————————-
CVE ID: CVE-2026-59788
CVSS score: 5.7 (Medium)
Affected components: Frontend
Summary: Stored XSS vulnerability in OAuth configuration form
Description: The email media type OAuth form passes the Authorization endpoint value to window.open() without validating the URL scheme, so a javascript: URL is executed in the browser. This means a crafted media type configuration, deliverable as an import file, runs arbitrary JavaScript as the Super Admin who grants consent.
Known attack vectors: Super Admin opening an attacker-supplied media type import file.
Affected and fix version/s:
Affected: 7.4.0 - 7.4.11 > Fixed: 7.4.12
Mitigation: Update the affected components to their respective fixed versions.
Workarounds: Don't import media type configurations from untrusted sources.
———————————————-
CVE ID: CVE-2026-59787
CVSS score: 5.3 (Medium)
Affected components: Server, Proxy
Summary: SNMP trap injection in zabbix_trap_receiver.pl
Description: The Perl SNMP trap receiver script shipped with Zabbix does not properly neutralize the ZBXTRAP record delimiter in trap content. This means someone able to send SNMP traps can inject a record targeting another host, resulting in a loss of integrity.
Known attack vectors: An attacker sending crafted SNMP trap payloads to the trap receiver.
Affected and fix version/s:
Affected: 6.0.0 - 6.0.47 > Fixed: 6.0.48
Affected: 7.0.0 - 7.0.28 > Fixed: 7.0.29
Affected: 7.4.0 - 7.4.12 > Fixed: 7.4.13
Mitigation: Update the affected components and replace the deployed zabbix_trap_receiver.pl with the fixed version.
Workarounds: None
———————————————-
CVE ID: CVE-2026-59785
CVSS score: 5.1 (Medium)
Affected components: Frontend
Summary: Hidden host credentials inferable via multiselect.get filtering
Description: Host search in Frontend allows filtering by fields that are not displayed, including stored IPMI and PSK credentials. A user with read access can guess a credential and see from the search result whether the guess was right, letting them uncover it.
Known attack vectors: An authenticated user with host read access sending crafted search queries.
Affected and fix version/s:
Affected: 6.0.0 - 6.0.47 > Fixed: 6.0.48
Affected: 7.0.0 - 7.0.28 > Fixed: 7.0.29
Affected: 7.4.0 - 7.4.12 > Fixed: 7.4.13
Mitigation: Update the affected components to their respective fixed versions.
Workarounds: None
———————————————-
CVE ID: CVE-2026-59783
CVSS score: 2.3 (Low)
Affected components: Server, Proxy
Summary: Server DoS via binary items
Description: The Zabbix Server/Proxy has a vulnerability where binary items can crash the Server/Proxy on certain NULL byte input leading to potential loss of availability. This only affects deployments where MySQL/MariaDB database is used as the Zabbix database.
Known attack vectors: An attacker with trapper access sending malicious data for binary items.
Affected and fix version/s:
Affected: 7.0.0 - 7.0.28 > Fixed: 7.0.29
Affected: 7.4.0 - 7.4.12 > Fixed: 7.4.13
Mitigation: Update the affected components to their respective fixed versions.
Workarounds: Disable item data collection for any Binary items with untrusted input.
Post #278
1.69K
- 👍 11
- 🔥 6
- ❤ 2