DEV Community

jeffrey
jeffrey

Posted on

CVE-2026-59782: a limited Zabbix administrator can read raw heap data through Duktape preprocessing

CVE-2026-59782: a limited Zabbix administrator can read raw heap data through Duktape preprocessing

Vulnerability overview

CVE-2026-59782 is part of the Zabbix vulnerability set published on 5 October 2026 and gathered in CERT-FR advisory CERTFR-2026-AVI-1261. The CVE record describes the JavaScript preprocessing engine: the Duktape engine on the Zabbix server has a vulnerability where a limited administrator is able to read raw heap data, potentially leaking data from other running preprocessors that the administrator is not entitled to see.

Mechanism and exploitation conditions

Zabbix preprocessing runs JavaScript through the Duktape engine to transform item values. Preprocessing scripts run server-side, and their memory contains the data of the items they handle.
The CVE record says a limited administrator can read raw heap data. A limited administrator is a role below Super Admin, which is what makes the flaw notable: the actor already holds administrative capability, and the bug lets them reach beyond the boundary of that role.
The leaked content is not arbitrary memory. The record scopes it to data from other running preprocessors, which means the exposure depends on what else is executing at the time. In a busy deployment handling values from many sources, the neighbouring data may be more sensitive than what the limited administrator is meant to see.

Impact

Preprocessing handles raw item values before they are stored or evaluated. Those values can include credentials, tokens, and internal identifiers that were never intended for a limited administrator.
The confidentiality boundary in Zabbix is meaningful. Teams assign limited administrator roles specifically to restrict what a person can observe. A read path around that boundary undermines the role model itself, not just one dataset, and it does so quietly, because a heap read leaves no obvious trace in the data.

Affected products and scope

The advisory lists affected ranges of Zabbix 6.0.x before 6.0.48, 7.0.x before 7.0.29, and 7.4.x before 7.4.13.
The flaw concerns the server-side JavaScript preprocessing engine, so deployments with preprocessing scripts are in scope. The CVE record does not report exploitation in the wild.

Exposure context

An AutoPR ZoomEye query on 5 October 2026 measured the public Zabbix footprint.
Search Dork: app="Zabbix"
ZoomEye returned 4,864 matching instances. The figure counts internet-visible assets fingerprinted as Zabbix. It says nothing about preprocessing usage or role assignments, which are the factors that determine this particular exposure.

Remediation and mitigations

Upgrade to 6.0.48, 7.0.29, or 7.4.13 or later, following the vendor bulletins referenced by the advisory.
Supporting measures:

  • Review who holds limited administrator roles and whether those grants are still justified.
  • Inventory which items use JavaScript preprocessing and, where practical, move sensitive transformation work off shared server-side scripts.
  • Assume that a role-boundary bug of this kind may have been used without obvious signs, and include relevant secrets in the rotation plan for affected instances.
  • After upgrading, test that a limited administrator cannot obtain neighbouring preprocessing data.
  • Keep preprocessing on a host that is patched promptly, because the engine runs with server privileges.

References

Top comments (0)