CVE-2026-59782: limited Zabbix admin can read raw heap data via Duktape
Zabbix disclosed CVE-2026-59782: a limited administrator can read raw heap data through the server-side Duktape JavaScript preprocessing engine, leaking data from other running preprocessors. Affected versions are 6.0.x before 6.0.48, 7.0.x before 7.0.29 and 7.4.x before 7.4.13; fixes are available.
- Flaw lets a limited admin read heap data from other preprocessors
- Affected: Zabbix 6.0.x < 6.0.48, 7.0.x < 7.0.29, 7.4.x < 7.4.13
- ZoomEye counted 4,864 internet-visible Zabbix instances on Oct 5, 2026
- No exploitation in the wild has been reported
Read next
Security