Authentication Bypass Vulnerability in Zabbix Server and Proxy
CVE-2026-59786

6.9MEDIUM

Key Information:

Vendor

Zabbix

Status
Vendor
CVE Published:
5 October 2026

What is CVE-2026-59786?

Zabbix Server and Proxy are susceptible to an authentication bypass issue where they accept active agent heartbeat messages irrespective of the configured pre-shared key (PSK) or certificate authentication. This vulnerability allows an unauthorized user with access to the Zabbix trapper port to falsely declare an arbitrary host as available, ultimately leading to a significant compromise of data integrity in the monitoring environment. Organizations using Zabbix should review their security configurations and apply necessary updates to mitigate this risk.

Affected Version(s)

Zabbix 7.0.0 <= 7.0.28

Zabbix 7.4.0 <= 7.4.12

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Zabbix wants to thank Aditya Bisht for submitting this report on the HackerOne bug bounty platform.
.