Zabbix 服务器和代理无论是否配置了预共享密钥(PSK)或证书认证,都会接受主动式代理的心跳消息。这意味着,任何能够访问 Zabbix Trapper 端口的人,都可以伪装任意主机,使其被报告为活跃的主动式代理在线状态,从而导致数据完整性受损。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-59782 | 6.9 MEDIUM | JavaScript preprocessing memory disclosure |
| CVE-2026-59788 | 5.6 MEDIUM | Stored XSS vulnerability in OAuth configuration form |
| CVE-2026-59787 | 5.3 MEDIUM | SNMP trap injection in zabbix_trap_receiver.pl |
| CVE-2026-59785 | 5.1 MEDIUM | Hidden host credentials inferable via multiselect.get filtering |
| CVE-2026-59783 | 2.3 LOW | Server DoS via binary items |
No comments yet