{"id":"CVE-2026-59785","title":"Host search in Frontend allows filtering by fields that are not displayed, including stored IPMI and PSK credentials","summary":"Host search in Frontend allows filtering by fields that are not displayed, including stored IPMI and PSK credentials. A user with read access can guess a credential and see from the search result whether the guess was right, letting them…","severity":"medium","cvss":5.1,"cvssVector":"CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N","cwe":["CWE-204"],"vendor":"Zabbix","product":"Zabbix","affected":["Zabbix >= 6.0.0 <= 6.0.47","Zabbix >= 7.0.0 <= 7.0.28","Zabbix >= 7.4.0 <= 7.4.12"],"published":"2026-10-05","updated":"2026-10-05","sourceUpdated":"2026-10-05T12:17:10.110","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-59785","references":[{"url":"https://support.zabbix.com/browse/ZBX-28195","label":"security@zabbix.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-10-05T11:41:31.643986Z"},"cvssSource":"cna","ingestedAt":"2026-10-05T11:18:17.203Z","slug":"CVE-2026-59785","body":"## Overview\n\nHost search in Frontend allows filtering by fields that are not displayed, including stored IPMI and PSK credentials. A user with read access can guess a credential and see from the search result whether the guess was right, letting them uncover it.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":28.1,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}