CVE-2026-59786: Active agent heartbeat missing TLS check
Published Oct 5, 2026
·Updated
Zabbix Server and Proxy accept the active agent heartbeat message regardless of the configured PSK or certificate authentication. This means someone with access to the Zabbix trapper port can report an arbitrary host using an active agent as available, resulting in a loss of integrity.
Affected Software
2 affected components
Zabbix Zabbix server
Zabbix Zabbix Proxy
Event History
Oct 5, 2026
CVE Published
via MITRE·10:29 AM
Data Sourced
via MITRE·10:29 AM
RemedyDescriptionWeakness
Data Sourced
via NVD·11:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access does an attacker need to manipulate host availability?
The attacker needs access to the Zabbix trapper port on a Zabbix Server or Proxy. The heartbeat message is accepted regardless of the configured PSK or certificate authentication.
2
Which hosts can have their availability status falsely reported?
Hosts that use an active Zabbix agent can be reported as available through an arbitrary heartbeat message. The stated impact is loss of integrity of availability reporting.