{"id":"CVE-2026-59786","title":"Zabbix Server and Proxy accept the active agent heartbeat message regardless of the configured PSK or certificate authentication","summary":"Zabbix Server and Proxy accept the active agent heartbeat message regardless of the configured PSK or certificate authentication. This means someone with access to the Zabbix trapper port can report an arbitrary host using an active agen…","severity":"medium","cvss":6.9,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N","cwe":["CWE-940"],"vendor":"Zabbix","product":"Zabbix","affected":["Zabbix >= 7.0.0 <= 7.0.28","Zabbix >= 7.4.0 <= 7.4.12"],"published":"2026-10-05","updated":"2026-10-05","sourceUpdated":"2026-10-05T12:17:10.230","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-59786","references":[{"url":"https://support.zabbix.com/browse/ZBX-28196","label":"security@zabbix.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"partial","timestamp":"2026-10-05T11:25:11.807987Z"},"cvssSource":"cna","ingestedAt":"2026-10-05T11:18:17.203Z","slug":"CVE-2026-59786","body":"## Overview\n\nZabbix Server and Proxy accept the active agent heartbeat message regardless of the configured PSK or certificate authentication. This means someone with access to the Zabbix trapper port can report an arbitrary host using an active agent as available, resulting in a loss of integrity.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":38,"depthScoreParts":{"impact":38,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}