CVE-2026-59785
Description
A flaw was found in Zabbix. The host search functionality in the web frontend allows filtering against fields that are not displayed, including stored Intelligent Platform Management Interface (IPMI) and Pre-Shared Key (PSK) credentials. An authenticated attacker with read access can exploit this by guessing values and observing search results to deduce and uncover sensitive credentials.
Statement
Red Hat does not ship Zabbix in any supported product. The community Fedora and EPEL packages are affected by this flaw and community trackers have been filed.
Mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Understanding the Weakness (CWE)
Confidentiality,Access Control
Technical Impact: Read Application Data; Bypass Protection Mechanism
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.