The JavaScript preprocessing (Duktape) engine on Zabbix server has a vulnerability where a limited administrator is able to read raw heap data potentially resulting in leaked data from other running preprocessors not available to said administrator.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
Update the affected components to their respective fixed versions.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://support.zabbix.com/browse/ZBX-28193 |
|
History
Mon, 05 Oct 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The JavaScript preprocessing (Duktape) engine on Zabbix server has a vulnerability where a limited administrator is able to read raw heap data potentially resulting in leaked data from other running preprocessors not available to said administrator. | |
| Title | JavaScript preprocessing memory disclosure | |
| Weaknesses | CWE-125 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Zabbix
Published:
Updated: 2026-10-05T11:53:36.626Z
Reserved: 2026-07-07T08:30:49.859Z
Link: CVE-2026-59782
No data.
Status : Received
Published: 2026-10-05T11:16:59.360
Modified: 2026-10-05T11:16:59.360
Link: CVE-2026-59782
No data.
OpenCVE Enrichment
Updated: 2026-10-05T11:30:17Z
Weaknesses