CVE-2026-59781
Zabbix Server vulnerability analysis and mitigation

Overview

CVE-2026-59781 is a DLL sideloading vulnerability in the Zabbix Agent Windows installer caused by improper validation of custom installation directories. When installed into a directory with insecure access permissions, an attacker with write access to that directory could place a malicious DLL that the application subsequently loads. Affected versions include Zabbix 6.0.0–6.0.47, 7.0.0–7.0.28, and 7.4.0–7.4.12. It was disclosed on August 18, 2026, and carries a CVSS v4.0 base score of 5.4 (Medium) (Zabbix Advisory).

Technical details

The root cause is an uncontrolled search path element (CWE-427) in the Zabbix Agent Windows installer, which failed to verify whether a user-selected custom installation directory had appropriately restricted access permissions. Because Windows resolves DLL dependencies by searching directories in a defined order, placing a malicious DLL in an insecure installation directory allows it to be loaded by the Zabbix Agent process — a technique known as DLL search order hijacking (MITRE ATT&CK T1574.001). Exploitation requires that the attacker already have write access to the target directory (low-privilege local access) and that passive user interaction (e.g., application restart or service start) occurs to trigger DLL loading. The fix hardens the installer to detect potentially unsafe directories and prompt for explicit user confirmation before proceeding (Zabbix Advisory).

Impact

Successful exploitation allows an attacker with local write access to an insecure installation directory to execute arbitrary code in the context of the Zabbix Agent process, resulting in high confidentiality, integrity, and availability impact on the vulnerable system. This could enable privilege escalation, persistent access, or lateral movement within the monitored environment, given that Zabbix Agents often run with elevated privileges to collect system metrics. The scope is limited to the vulnerable component itself, with no direct impact on other system components (Zabbix Advisory).

Exploitability

No public proof-of-concept exploit code or in-the-wild exploitation has been reported as of the disclosure date. The NVD SSVC assessment classifies exploitation as "none" and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The EPSS score is 0.0, reflecting a very low probability of near-term exploitation. Exploitation is not automatable, as it requires local access and passive user interaction (Zabbix Advisory).

Exploitation steps

  1. Reconnaissance: Identify Windows hosts running Zabbix Agent installed into a non-default, custom directory (e.g., via local enumeration or access to deployment records).
  2. Check directory permissions: Use tools such as icacls or accesschk to verify that the custom installation directory grants write permissions to unprivileged users or the attacker's account.
  3. Craft malicious DLL: Create a malicious DLL with the same name as a legitimate DLL expected to be loaded by the Zabbix Agent (e.g., a dependency resolved via the Windows DLL search order).
  4. Place the DLL: Copy the malicious DLL into the insecure installation directory, exploiting the write permissions available to the attacker.
  5. Trigger DLL load: Wait for or trigger a Zabbix Agent service restart (e.g., via system reboot, service manager, or scheduled task), causing the application to load the malicious DLL from the insecure directory.
  6. Achieve code execution: The malicious DLL executes in the context of the Zabbix Agent process, enabling arbitrary code execution, persistence, or further lateral movement (Zabbix Advisory).

Indicators of compromise

  • File System: Unexpected or newly created DLL files in the Zabbix Agent custom installation directory, particularly DLLs not part of the original installation package; file timestamps inconsistent with the installation date.
  • Process: Unusual child processes or network connections spawned by the Zabbix Agent process (zabbix_agentd.exe); unexpected DLLs loaded by the agent process (detectable via tools like Process Monitor or Sysmon Event ID 7).
  • Logs: Windows Event Log entries (e.g., Event ID 7045 or 7036) showing unexpected service restarts of the Zabbix Agent; Sysmon Image Load events (Event ID 7) for unsigned or unexpected DLLs loaded by zabbix_agentd.exe.
  • Registry: Changes to Zabbix Agent service registry keys (e.g., HKLM\SYSTEM\CurrentControlSet\Services\Zabbix Agent) that alter the binary path or startup parameters.

Mitigation and workarounds

Zabbix has released fixed versions that harden the installer to detect unsafe installation directories: 6.0.48 (for the 6.0.x branch), 7.0.29 (for the 7.0.x branch), and 7.4.13 (for the 7.4.x branch). Organizations should upgrade to these fixed versions as the primary remediation. As an interim workaround, ensure the Zabbix Agent installation directory has appropriately restricted permissions — only the SYSTEM account and administrators should have write access — and audit existing custom installation directories using icacls to identify and remediate overly permissive ACLs (Zabbix Advisory).

Community reactions

The vulnerability was discovered and reported by Kazuma Matsumoto of GMO Cybersecurity by IERAE, Inc., and Zabbix acknowledged the responsible disclosure in their advisory. No significant broader industry commentary or social media discussion has been identified as of the disclosure date (Zabbix Advisory).

Additional resources


SourceThis report was generated using AI

Related Zabbix Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-23935MEDIUM6.8
  • Zabbix Server logoZabbix Server
  • zabbix
NoNoAug 18, 2026
CVE-2026-23937MEDIUM6
  • Zabbix Server logoZabbix Server
  • zabbix
NoNoAug 18, 2026
CVE-2026-59781MEDIUM5.4
  • Zabbix Server logoZabbix Server
  • zabbix
NoNoAug 18, 2026
CVE-2026-23934MEDIUM5.1
  • Zabbix Server logoZabbix Server
  • cpe:2.3:a:zabbix:zabbix
NoNoAug 18, 2026
CVE-2026-23938LOW2.1
  • Zabbix Server logoZabbix Server
  • cpe:2.3:a:zabbix:zabbix
NoNoAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management