CVE-2026-59785: Hidden host credentials inferable via multiselect.get filtering
Published Oct 5, 2026
·Updated
Host search in Frontend allows filtering by fields that are not displayed, including stored IPMI and PSK credentials. A user with read access can guess a credential and see from the search result whether the guess was right, letting them uncover it.
Affected Software
1 affected component
Zabbix Zabbix frontend
Event History
Oct 5, 2026
CVE Published
via MITRE·10:28 AM
Data Sourced
via MITRE·10:28 AM
RemedyDescriptionWeakness
Data Sourced
via NVD·11:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
A user with read access who can use host search in the frontend can exploit it. The issue is exposed through filtering on fields that are not displayed in search results.
2
What does an attacker need to recover a credential?
The attacker needs a candidate value to guess for a stored IPMI or PSK credential. Search results reveal whether the guessed value matches the hidden credential.