CVE-2026-59781

NameCVE-2026-59781
DescriptionWhen Zabbix Agent was installed on Windows into a custom installation directory, the installer did not verify whether the selected directory had secure access permissions. If the target directory allowed unauthorized users to modify its contents, an attacker could place a malicious DLL that could later be loaded by the application, resulting in DLL sideloading. The installer has been hardened to detect potentially unsafe installation directories and now requires explicit user confirmation before proceeding with installation in such locations. This reduces the risk of accidental installation into directories with inappropriate permissions while preserving compatibility with existing deployment scenarios.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
zabbix (PTS)bullseye1:5.0.8+dfsg-1fixed
bullseye (security)1:5.0.47+dfsg-0+deb11u1fixed
bookworm1:6.0.14+dfsg-1fixed
trixie1:7.0.22+dfsg-1~deb13u1fixed
sid1:7.0.22+dfsg-1.1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
zabbixsource(unstable)(not affected)

Notes

- zabbix <not-affected> (Windows-specific)
https://support.zabbix.com/browse/ZBX-28077

Search for package or bug name: Reporting problems