CVE-2026-59785: fallo de gravedad media en Zabbix
Hidden host credentials inferable via multiselect.get filtering
Publicada el
13Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 5.1epss 0.2%
probabilidad de explotación
0.2%top 96% de las CVE
explotación observada
noninguna fuente lo reporta
Host search in Frontend allows filtering by fields that are not displayed, including stored IPMI and PSK credentials. A user with read access can guess a credential and see from the search result whether the guess was right, letting them uncover it.
CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Productos afectados
Zabbix · ZabbixCVEs relacionadas — Zabbix
En el mismo producto, de las más peligrosas a las menos.
CVE-2024-42327CRITICALSQL injection in user.get APIEPSS 78.7%CVE-2024-22120CRITICALTime Based SQL Injection in Zabbix Server Audit LogEPSS 76.6%CVE-2013-3628—CVE-2013-3628EPSS 67.5%CVE-2023-29452MEDIUMRemove possibility to add html into Geomap attribution fieldEPSS 64.1%CVE-2024-36465HIGHSQL injection in Zabbix APIEPSS 39.9%CVE-2026-23921HIGHBlind, read-only SQL injection in Zabbix API via sortfield parameterEPSS 3.9%
Referencias
https://support.zabbix.com/browse/ZBX-28195