{"id":"CVE-2026-59782","title":"The JavaScript preprocessing (Duktape) engine on Zabbix server has a vulnerability where a limited administrator is able to read raw heap data potentially resulting in leaked data from other running preprocessors not available to said ad…","summary":"The JavaScript preprocessing (Duktape) engine on Zabbix server has a vulnerability where a limited administrator is able to read raw heap data potentially resulting in leaked data from other running preprocessors not available to said ad…","severity":"medium","cvss":6.9,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N","cwe":["CWE-125"],"vendor":"Zabbix","product":"Zabbix","affected":["Zabbix >= 6.0.0 <= 6.0.47","Zabbix >= 7.0.0 <= 7.0.28","Zabbix >= 7.4.0 <= 7.4.12"],"published":"2026-10-05","updated":"2026-10-05","sourceUpdated":"2026-10-05T12:17:09.877","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-59782","references":[{"url":"https://support.zabbix.com/browse/ZBX-28193","label":"security@zabbix.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-10-05T11:52:57.407878Z"},"cvssSource":"cna","ingestedAt":"2026-10-05T11:18:17.202Z","slug":"CVE-2026-59782","body":"## Overview\n\nThe JavaScript preprocessing (Duktape) engine on Zabbix server has a vulnerability where a limited administrator is able to read raw heap data potentially resulting in leaked data from other running preprocessors not available to said administrator.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":38,"depthScoreParts":{"impact":38,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}