CVE-2026-59782
EUVD-2026-9239505.10.2026, 11:16
The JavaScript preprocessing (Duktape) engine on Zabbix server has a vulnerability where a limited administrator is able to read raw heap data potentially resulting in leaked data from other running preprocessors not available to said administrator.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| zabbix | zabbix | 6.0.0 ≤ 𝑥 ≤ 6.0.47 | CNA |
| zabbix | zabbix | 7.0.0 ≤ 𝑥 ≤ 7.0.28 | CNA |
| zabbix | zabbix | 7.4.0 ≤ 𝑥 ≤ 7.4.12 | CNA |
Debian Releases
Common Weakness Enumeration
Vulnerability Media Exposure