Impact
Zabbix Server and Proxy accept active agent heartbeat messages without validating the pre‑shared key or TLS certificate. Because the authentication check is bypassed, any host connected to the trapper port can send a heartbeat that is treated as a legitimate active agent ping. This allows an attacker to make the monitoring system believe that an arbitrary host is online, corrupting the integrity of host status information. The flaw is a validation error that permits the use of authentication credentials that are not checked, mapping to CWE‑940.
Affected Systems
The issue affects Zabbix Server and Zabbix Proxy components. It applies to all versions that have not yet incorporated the patch described in the Zabbix support ticket ZBX‑28196. The fix is included in the updated component releases dated after that ticket. Administrators should review their installed versions for the presence of the bug.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity. Because the vulnerability can be triggered by any entity that can connect to the trapper port (default 10050), the exploitability is high in environments where the port is exposed. No publicly available exploit has been reported and the vulnerability is not listed in CISA KEV, but the lack of authentication means an attacker can easily craft a false heartbeat. The EPSS score is not available, but the moderate CVSS combined with the network‑based attack vector suggests that organizations using exposed Zabbix services should treat this as a high‑risk issue.
OpenCVE Enrichment