Description
Zabbix Server and Proxy accept the active agent heartbeat message regardless of the configured PSK or certificate authentication. This means someone with access to the Zabbix trapper port can report an arbitrary host using an active agent as available, resulting in a loss of integrity.
Published: 2026-10-05
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Integrity loss due to false host availability
Action: Immediate Patch
AI Analysis

Impact

Zabbix Server and Proxy accept active agent heartbeat messages without validating the pre‑shared key or TLS certificate. Because the authentication check is bypassed, any host connected to the trapper port can send a heartbeat that is treated as a legitimate active agent ping. This allows an attacker to make the monitoring system believe that an arbitrary host is online, corrupting the integrity of host status information. The flaw is a validation error that permits the use of authentication credentials that are not checked, mapping to CWE‑940.

Affected Systems

The issue affects Zabbix Server and Zabbix Proxy components. It applies to all versions that have not yet incorporated the patch described in the Zabbix support ticket ZBX‑28196. The fix is included in the updated component releases dated after that ticket. Administrators should review their installed versions for the presence of the bug.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate severity. Because the vulnerability can be triggered by any entity that can connect to the trapper port (default 10050), the exploitability is high in environments where the port is exposed. No publicly available exploit has been reported and the vulnerability is not listed in CISA KEV, but the lack of authentication means an attacker can easily craft a false heartbeat. The EPSS score is not available, but the moderate CVSS combined with the network‑based attack vector suggests that organizations using exposed Zabbix services should treat this as a high‑risk issue.

Generated by OpenCVE AI on October 5, 2026 at 11:21 UTC.

Remediation

Vendor Solution

Update the affected components to their respective fixed versions.


OpenCVE Recommended Actions

  • Apply the updated Zabbix Server and Proxy releases that contain the fix.
  • Restrict access to the Zabbix trapper port (default 10050) with firewalls or network segmentation so that only trusted hosts can reach it.
  • Verify that active agent authentication is enabled and correctly configured to use PSK or certificates and enforce these settings in the Zabbix configuration.

Generated by OpenCVE AI on October 5, 2026 at 11:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 05 Oct 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Zabbix
Zabbix zabbix
Vendors & Products Zabbix
Zabbix zabbix

Mon, 05 Oct 2026 10:45:00 +0000

Type Values Removed Values Added
Description Zabbix Server and Proxy accept the active agent heartbeat message regardless of the configured PSK or certificate authentication. This means someone with access to the Zabbix trapper port can report an arbitrary host using an active agent as available, resulting in a loss of integrity.
Title Active agent heartbeat missing TLS check
Weaknesses CWE-940
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Zabbix

Published:

Updated: 2026-10-05T11:25:27.518Z

Reserved: 2026-07-07T08:30:49.860Z

Link: CVE-2026-59786

cve-icon Vulnrichment

Updated: 2026-10-05T11:25:18.118Z

cve-icon NVD

Status : Received

Published: 2026-10-05T11:16:59.807

Modified: 2026-10-05T12:17:10.230

Link: CVE-2026-59786

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T11:30:17Z

Weaknesses
  • CWE-940

    Improper Verification of Source of a Communication Channel