Published:2026/08/28  Last Updated:2026/08/28

JVN#42011956
Zabbix agent may insecurely load Dynamic Link Libraries

Overview

Zabbix agent provided by Zabbix LLC may insecurely load Dynamic Link Libraries.

Products Affected

  • Zabbix agent versions prior to 7.0.24
  • Zabbix agent versions prior to 7.4.8

Description

Zabbix agent provided by Zabbix LLC may load Dynamic Link Libraries insecurely due to the following vulnerability.

  • Incorrect default permissions (CWE-276)
    • CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Base Score 5.4
    • CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H Base Score 6.7
    • CVE-2026-59781

Impact

Arbitrary code may be executed with the administrator privilege.

Solution

Update the Software
Update the software to the latest version according to the information provided by the developer.

Vendor Status

Vendor Link
Zabbix LLC Release Notes

References

JPCERT/CC Addendum

Vulnerability Analysis by JPCERT/CC

Credit

Kazuma Matsumoto of GMO Cybersecurity by IERAE, Inc. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE
JVN iPedia JVNDB-2026-000124