Authentication Bypass Vulnerability in Zabbix Server and Proxy
CVE-2026-59786
6.9MEDIUM
What is CVE-2026-59786?
Zabbix Server and Proxy are susceptible to an authentication bypass issue where they accept active agent heartbeat messages irrespective of the configured pre-shared key (PSK) or certificate authentication. This vulnerability allows an unauthorized user with access to the Zabbix trapper port to falsely declare an arbitrary host as available, ultimately leading to a significant compromise of data integrity in the monitoring environment. Organizations using Zabbix should review their security configurations and apply necessary updates to mitigate this risk.
Affected Version(s)
Zabbix 7.0.0 <= 7.0.28
Zabbix 7.4.0 <= 7.4.12
References
CVSS V4
Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Zabbix wants to thank Aditya Bisht for submitting this report on the HackerOne bug bounty platform.
