Published:2026/08/28 Last Updated:2026/08/28
JVN#42011956
Zabbix agent may insecurely load Dynamic Link Libraries
Overview
Zabbix agent provided by Zabbix LLC may insecurely load Dynamic Link Libraries.
Products Affected
- Zabbix agent versions prior to 7.0.24
- Zabbix agent versions prior to 7.4.8
Description
Zabbix agent provided by Zabbix LLC may load Dynamic Link Libraries insecurely due to the following vulnerability.
- Incorrect default permissions (CWE-276)
- CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Base Score 5.4
- CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H Base Score 6.7
- CVE-2026-59781
Impact
Arbitrary code may be executed with the administrator privilege.
Solution
Update the Software
Update the software to the latest version according to the information provided by the developer.
Vendor Status
| Vendor | Link |
| Zabbix LLC | Release Notes |
References
JPCERT/CC Addendum
Vulnerability Analysis by JPCERT/CC
Credit
Kazuma Matsumoto of GMO Cybersecurity by IERAE, Inc. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
Other Information
| JPCERT Alert |
|
| JPCERT Reports |
|
| CERT Advisory |
|
| CPNI Advisory |
|
| TRnotes |
|
| CVE |
|
| JVN iPedia |
JVNDB-2026-000124 |