CVE-2026-59783

Summary

The Zabbix Server/Proxy has a vulnerability where binary items can crash the Server/Proxy on certain NULL byte input leading to potential loss of availability. This only affects deployments where MySQL/MariaDB database is used as the Zabbix database.

Affected Software

VendorProductVersion RangeStatus
ZabbixZabbix7.0.0 <= 7.0.28affected
ZabbixZabbix7.4.0 <= 7.4.12affected

Weaknesses

  • CWE-787: CWE-787: Out-of-bounds Write

Workarounds

Disable item data collection for any Binary items with untrusted input.

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References