CVE-2026-59786

EUVD-2026-92398
Zabbix Server and Proxy accept the active agent heartbeat message regardless of the configured PSK or certificate authentication. This means someone with access to the Zabbix trapper port can report an arbitrary host using an active agent as available, resulting in a loss of integrity.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
ZabbixCNA
6.9 MEDIUM
NETWORK
LOW
NONE
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
zabbixzabbix
7.0.0 ≤
𝑥
≤ 7.0.28
CNA
zabbixzabbix
7.4.0 ≤
𝑥
≤ 7.4.12
CNA
Debian logo
Debian Releases
Debian Product
Codename
zabbix
bookworm
vulnerable
forky
1:7.0.29+dfsg-2
fixed
sid
1:7.0.29+dfsg-2
fixed
trixie
vulnerable