CVE-2026-59785: Zabbix
Medium severity, CVSS 5.1. EPSS: 0.2% chance of exploitation in the next 30 days.
Host search in Frontend allows filtering by fields that are not displayed, including stored IPMI and PSK credentials. A user with read access can guess a credential and see from the search result whether the guess was right, letting them uncover it.
Affected products
- Zabbix Zabbix
Published 2026-10-05. Last modified 2026-10-06.