
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-59781 is a DLL sideloading vulnerability in the Zabbix Agent Windows installer caused by improper validation of custom installation directories. When installed into a directory with insecure access permissions, an attacker with write access to that directory could place a malicious DLL that the application subsequently loads. Affected versions include Zabbix 6.0.0–6.0.47, 7.0.0–7.0.28, and 7.4.0–7.4.12. It was disclosed on August 18, 2026, and carries a CVSS v4.0 base score of 5.4 (Medium) (Zabbix Advisory).
The root cause is an uncontrolled search path element (CWE-427) in the Zabbix Agent Windows installer, which failed to verify whether a user-selected custom installation directory had appropriately restricted access permissions. Because Windows resolves DLL dependencies by searching directories in a defined order, placing a malicious DLL in an insecure installation directory allows it to be loaded by the Zabbix Agent process — a technique known as DLL search order hijacking (MITRE ATT&CK T1574.001). Exploitation requires that the attacker already have write access to the target directory (low-privilege local access) and that passive user interaction (e.g., application restart or service start) occurs to trigger DLL loading. The fix hardens the installer to detect potentially unsafe directories and prompt for explicit user confirmation before proceeding (Zabbix Advisory).
Successful exploitation allows an attacker with local write access to an insecure installation directory to execute arbitrary code in the context of the Zabbix Agent process, resulting in high confidentiality, integrity, and availability impact on the vulnerable system. This could enable privilege escalation, persistent access, or lateral movement within the monitored environment, given that Zabbix Agents often run with elevated privileges to collect system metrics. The scope is limited to the vulnerable component itself, with no direct impact on other system components (Zabbix Advisory).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported as of the disclosure date. The NVD SSVC assessment classifies exploitation as "none" and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The EPSS score is 0.0, reflecting a very low probability of near-term exploitation. Exploitation is not automatable, as it requires local access and passive user interaction (Zabbix Advisory).
icacls or accesschk to verify that the custom installation directory grants write permissions to unprivileged users or the attacker's account.zabbix_agentd.exe); unexpected DLLs loaded by the agent process (detectable via tools like Process Monitor or Sysmon Event ID 7).zabbix_agentd.exe.HKLM\SYSTEM\CurrentControlSet\Services\Zabbix Agent) that alter the binary path or startup parameters.Zabbix has released fixed versions that harden the installer to detect unsafe installation directories: 6.0.48 (for the 6.0.x branch), 7.0.29 (for the 7.0.x branch), and 7.4.13 (for the 7.4.x branch). Organizations should upgrade to these fixed versions as the primary remediation. As an interim workaround, ensure the Zabbix Agent installation directory has appropriately restricted permissions — only the SYSTEM account and administrators should have write access — and audit existing custom installation directories using icacls to identify and remediate overly permissive ACLs (Zabbix Advisory).
The vulnerability was discovered and reported by Kazuma Matsumoto of GMO Cybersecurity by IERAE, Inc., and Zabbix acknowledged the responsible disclosure in their advisory. No significant broader industry commentary or social media discussion has been identified as of the disclosure date (Zabbix Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."