CVE-2026-59782
Received Received - Intake

Heap Data Leak in Zabbix Server Duktape Engine

Vulnerability report for CVE-2026-59782, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: Zabbix

Description

The JavaScript preprocessing (Duktape) engine on Zabbix server has a vulnerability where a limited administrator is able to read raw heap data potentially resulting in leaked data from other running preprocessors not available to said administrator.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
Zabbix Zabbix 6.0.0
Zabbix Zabbix 7.0.0
Zabbix Zabbix 7.4.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability exists in the JavaScript preprocessing engine (Duktape) of the Zabbix server. A limited administrator account can read raw heap data, potentially accessing sensitive information from other running preprocessors that should not be visible to them.

Detection Guidance

This vulnerability involves a limited administrator reading raw heap data from Zabbix server's Duktape engine. Detection requires checking Zabbix server logs for unusual data access patterns or unauthorized memory reads. No specific commands are provided in the context to detect this issue.

Impact Analysis

An attacker with limited administrator privileges could exploit this to access confidential data from other processes, leading to unauthorized information disclosure. This could include sensitive configuration details or user data handled by other preprocessors.

Compliance Impact

This vulnerability could lead to unauthorized data exposure, violating GDPR's data protection principles or HIPAA's confidentiality requirements. Organizations may face compliance violations, legal penalties, and reputational damage if exploited.

Mitigation Strategies

Update Zabbix server to the latest patched version to address the Duktape engine vulnerability. Restrict administrator privileges to only necessary users and monitor for unusual heap data access patterns.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-59782. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart