Zabbix 服务器的 JavaScript 预处理引擎(Duktape)存在一个漏洞,导致受限管理员能够读取原始堆数据,从而可能导致从其他正在运行的预处理器中泄漏该管理员无权访问的数据。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-59786 | 6.9 MEDIUM | Active agent heartbeat missing TLS check |
| CVE-2026-59788 | 5.6 MEDIUM | Stored XSS vulnerability in OAuth configuration form |
| CVE-2026-59787 | 5.3 MEDIUM | SNMP trap injection in zabbix_trap_receiver.pl |
| CVE-2026-59785 | 5.1 MEDIUM | Hidden host credentials inferable via multiselect.get filtering |
| CVE-2026-59783 | 2.3 LOW | Server DoS via binary items |
No comments yet