Description
Host search in Frontend allows filtering by fields that are not displayed, including stored IPMI and PSK credentials. A user with read access can guess a credential and see from the search result whether the guess was right, letting them uncover it.
Published: 2026-10-05
Score: 5.1 Medium
EPSS: n/a
KEV: No
Impact: Information Disclosure via credential inference
Action: Assess Impact
AI Analysis

Impact

Host search functionality in Zabbix’s web interface permits filtering on hidden fields, such as stored IPMI and pre‑shared key credentials. A user with read‑level access can supply a guess for a credential, submit the search request, and examine the returned records to see if the guess matches a stored value. This observation allows the attacker to infer the exact credentials over repeated attempts, eventually revealing sensitive host authentication data. The vulnerability represents an information disclosure flaw (CWE‑204).

Affected Systems

Zabbix, the widely deployed monitoring platform, is affected. The flaw impacts any Zabbix installation that employs the frontend host‑search feature and stores IPMI or PSK credentials. Specific product versions or build numbers are not listed in the advisory; administrators should verify that their deployment includes the affected component before patching.

Risk and Exploitability

With a CVSS score of 5.1, the flaw is considered moderate severity. No EPSS score is available, and the vulnerability is not listed in CISA’s Known Exploited Vulnerabilities catalog. The likely attack vector is via the web interface; an attacker needs authenticated read access and the ability to submit search queries. Because credential guesses are verified through search results, the risk escalates with the number of guesses an attacker can make.

Generated by OpenCVE AI on October 5, 2026 at 11:22 UTC.

Remediation

Vendor Solution

Update the affected components to their respective fixed versions.


OpenCVE Recommended Actions

  • Apply the vendor‑supplied patch or upgrade Zabbix to a fixed release.
  • Restrict read‑level access for users who do not need host‑search functionality, limiting their ability to perform credential inference.
  • Review and, if possible, remove stored IPMI and PSK credentials or disable searching on these hidden fields in the frontend configuration.

Generated by OpenCVE AI on October 5, 2026 at 11:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 05 Oct 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Zabbix
Zabbix zabbix
Vendors & Products Zabbix
Zabbix zabbix

Mon, 05 Oct 2026 10:45:00 +0000

Type Values Removed Values Added
Description Host search in Frontend allows filtering by fields that are not displayed, including stored IPMI and PSK credentials. A user with read access can guess a credential and see from the search result whether the guess was right, letting them uncover it.
Title Hidden host credentials inferable via multiselect.get filtering
Weaknesses CWE-204
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Zabbix

Published:

Updated: 2026-10-05T11:43:32.737Z

Reserved: 2026-07-07T08:30:49.860Z

Link: CVE-2026-59785

cve-icon Vulnrichment

Updated: 2026-10-05T11:43:06.211Z

cve-icon NVD

Status : Received

Published: 2026-10-05T11:16:59.667

Modified: 2026-10-05T12:17:10.110

Link: CVE-2026-59785

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T11:30:17Z

Weaknesses
  • CWE-204

    Observable Response Discrepancy