CVE-2026-59786
Received Received - Intake

Zabbix Server and Proxy Authentication Bypass via Active Agent Heartbeat

Vulnerability report for CVE-2026-59786, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: Zabbix

Description

Zabbix Server and Proxy accept the active agent heartbeat message regardless of the configured PSK or certificate authentication. This means someone with access to the Zabbix trapper port can report an arbitrary host using an active agent as available, resulting in a loss of integrity.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
Zabbix Zabbix 7.0.0
Zabbix Zabbix 7.4.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-940 The product establishes a communication channel to handle an incoming request that has been initiated by an actor, but it does not properly verify that the request is coming from the expected origin.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Zabbix Server and Proxy do not properly validate active agent heartbeat messages when PSK or certificate authentication is configured. This allows an attacker with access to the Zabbix trapper port to falsely report a host as available, compromising the integrity of the monitoring system.

Detection Guidance

This vulnerability allows unauthorized reporting of hosts as available via the Zabbix trapper port. To detect it, monitor the trapper port (default 10051) for unexpected active agent heartbeat messages. Check Zabbix server logs for unusual host registrations or heartbeat events from unknown sources. Use network monitoring tools like tcpdump to capture traffic on the trapper port and analyze for anomalies.

Impact Analysis

This vulnerability could lead to false availability reports, causing incorrect monitoring data. It may result in missed alerts for actual outages or false alarms, disrupting incident response and system reliability.

Compliance Impact

This vulnerability allows unauthorized reporting of hosts as available, which could lead to false data integrity in monitoring systems. This may impact compliance by compromising the accuracy of logs and records required for audits under standards like GDPR and HIPAA.

Mitigation Strategies

Ensure proper PSK or certificate authentication is enforced for active agent heartbeat messages. Restrict access to the Zabbix trapper port to trusted sources only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-59786. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart