The JavaScript preprocessing (Duktape) engine on Zabbix server has a vulnerability where a limited administrator is able to read raw heap data potentially resulting in leaked data from other running preprocessors not available to said administrator.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
Update the affected components to their respective fixed versions.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://support.zabbix.com/browse/ZBX-28193 |
|
History
Mon, 05 Oct 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The JavaScript preprocessing (Duktape) engine on Zabbix server has a vulnerability where a limited administrator is able to read raw heap data potentially resulting in leaked data from other running preprocessors not available to said administrator. | |
| Title | JavaScript preprocessing memory disclosure | |
| Weaknesses | CWE-125 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Zabbix
Published:
Updated: 2026-10-05T11:53:36.626Z
Reserved: 2026-07-07T08:30:49.859Z
Link: CVE-2026-59782
No data.
Status : Received
Published: 2026-10-05T11:16:59.360
Modified: 2026-10-05T11:16:59.360
Link: CVE-2026-59782
No data.
OpenCVE Enrichment
Updated: 2026-10-05T11:30:17Z
Weaknesses