---
id: CVE-2026-59786
title: >-
  Zabbix Server and Proxy accept the active agent heartbeat message regardless
  of the configured PSK or certificate authentication
summary: >-
  Zabbix Server and Proxy accept the active agent heartbeat message regardless
  of the configured PSK or certificate authentication. This means someone with
  access to the Zabbix trapper port can report an arbitrary host using an active
  agen…
severity: medium
cvss: 6.9
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'
cwe:
  - CWE-940
vendor: Zabbix
product: Zabbix
affected:
  - Zabbix >= 7.0.0 <= 7.0.28
  - Zabbix >= 7.4.0 <= 7.4.12
published: '2026-10-05'
updated: '2026-10-05'
sourceUpdated: '2026-10-05T12:17:10.230'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-59786'
references:
  - url: 'https://support.zabbix.com/browse/ZBX-28196'
    label: security@zabbix.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-10-05T11:25:11.807987Z'
cvssSource: cna
ingestedAt: '2026-10-05T11:18:17.203Z'
---

## Overview

Zabbix Server and Proxy accept the active agent heartbeat message regardless of the configured PSK or certificate authentication. This means someone with access to the Zabbix trapper port can report an arbitrary host using an active agent as available, resulting in a loss of integrity.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
