TGViewer
Zabbix Recipes Zabbix Recipes @zabbix_ru · 3.61K subscribers
Post #278 1.69K
Новый пакет найденных в Zabbix уязвимостей и способы их устранения. Не забывайте обновляться.

———————————————-

CVE ID: 
CVE-2026-59782

CVSS score: 6.9 (Medium)

Affected components: Server, Proxy

Summary: JavaScript preprocessing memory disclosure

Description: The JavaScript preprocessing (Duktape) engine on Zabbix server has a vulnerability where a limited administrator is able to read raw heap data potentially resulting in leaked data from other running preprocessors not available to said administrator.

Known attack vectors: An attacker with limited administrator access to the Zabbix Frontend can define malicious preprocessing rules.

Affected and fix version/s:

Affected: 6.0.0 - 6.0.47 > Fixed: 6.0.48
Affected: 7.0.0 - 7.0.28 > Fixed: 7.0.29
Affected: 7.4.0 - 7.4.12 > Fixed: 7.4.13

Mitigation: Update the affected components to their respective fixed versions.

Workarounds: None

———————————————-

CVE ID: CVE-2026-59786

CVSS score: 6.9 (Medium)

Affected components: Server, Proxy

Summary: Active agent heartbeat missing TLS check

Description: Zabbix Server and Proxy accept the active agent heartbeat message regardless of the configured PSK or certificate authentication. This means someone with access to the Zabbix trapper port can report an arbitrary host using an active agent as available, resulting in a loss of integrity.

Known attack vectors: An attacker with network access to the trapper port sending crafted heartbeat packets.

Affected and fix version/s:

Affected: 7.0.0 - 7.0.28 > Fixed: 7.0.29
Affected: 7.4.0 - 7.4.12 > Fixed: 7.4.13

Mitigation: Update the affected components to their respective fixed versions.

Workarounds: None

———————————————-

CVE ID: CVE-2026-59788

CVSS score: 5.7 (Medium)

Affected components: Frontend

Summary: Stored XSS vulnerability in OAuth configuration form

Description: The email media type OAuth form passes the Authorization endpoint value to window.open() without validating the URL scheme, so a javascript: URL is executed in the browser. This means a crafted media type configuration, deliverable as an import file, runs arbitrary JavaScript as the Super Admin who grants consent.

Known attack vectors: Super Admin opening an attacker-supplied media type import file.

Affected and fix version/s:

​​​Affected: 7.4.0 - 7.4.11 > Fixed: 7.4.12

Mitigation: Update the affected components to their respective fixed versions.

Workarounds: Don't import media type configurations from untrusted sources.

———————————————-

CVE ID: CVE-2026-59787

CVSS score: 5.3 (Medium)

Affected components: Server, Proxy

Summary: SNMP trap injection in zabbix_trap_receiver.pl

Description: The Perl SNMP trap receiver script shipped with Zabbix does not properly neutralize the ZBXTRAP record delimiter in trap content. This means someone able to send SNMP traps can inject a record targeting another host, resulting in a loss of integrity.

Known attack vectors: An attacker sending crafted SNMP trap payloads to the trap receiver.

Affected and fix version/s:

Affected: 6.0.0 - 6.0.47 > Fixed: 6.0.48
Affected: 7.0.0 - 7.0.28 > Fixed: 7.0.29
Affected: 7.4.0 - 7.4.12 > Fixed: 7.4.13

Mitigation: Update the affected components and replace the deployed zabbix_trap_receiver.pl with the fixed version.

Workarounds: None

———————————————-

CVE ID: CVE-2026-59785

CVSS score: 5.1 (Medium)

Affected components: Frontend

Summary: Hidden host credentials inferable via multiselect.get filtering

Description: Host search in Frontend allows filtering by fields that are not displayed, including stored IPMI and PSK credentials. A user with read access can guess a credential and see from the search result whether the guess was right, letting them uncover it.

Known attack vectors: An authenticated user with host read access sending crafted search queries.

Affected and fix version/s:

Affected: 6.0.0 - 6.0.47 > Fixed: 6.0.48
Affected: 7.0.0 - 7.0.28 > Fixed: 7.0.29
Affected: 7.4.0 - 7.4.12 > Fixed: 7.4.13

Mitigation: Update the affected components to their respective fixed versions.

Workarounds: None

———————————————-

CVE ID: CVE-2026-59783

CVSS score: 2.3 (Low)

Affected components: Server, Proxy

Summary: Server DoS via binary items

Description: The Zabbix Server/Proxy has a vulnerability where binary items can crash the Server/Proxy on certain NULL byte input leading to potential loss of availability. This only affects deployments where MySQL/MariaDB database is used as the Zabbix database.

Known attack vectors: An attacker with trapper access sending malicious data for binary items.

Affected and fix version/s:

Affected: 7.0.0 - 7.0.28 > Fixed: 7.0.29
Affected: 7.4.0 - 7.4.12 > Fixed: 7.4.13

Mitigation: Update the affected components to their respective fixed versions.

Workarounds: Disable item data collection for any Binary items with untrusted input.
  • 👍 11
  • 🔥 6
  • ❤ 2
More from @zabbix_ru
  1. Sep 14, 2026🚀 Zabbix 8.0 на подходе. Запланируйте обучение команды уже сейчас В ближайшее время ожида…
  2. Sep 10, 2026zabbix-network-topology Модуль Zabbix 7.0 LTS/7.4 для интерактивной визуализации топологии…
  3. Sep 2, 2026Уже скоро!
  4. Sep 1, 2026Уже на следующей неделе — с 7 по 11 сентября — мы проведём тренинг Zabbix Certified Specia…
  5. Aug 13, 2026Zabbix Handy Tips: Creating Hierarchical Host Group Permission Structure В этом видео кома…
  6. Jul 29, 2026🎓 Официальный сертификат Zabbix — больше, чем просто документ При выборе обучения многие…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →