What is CVE-2026-59781?
CVE-2026-59781 relates to Zabbix Agent installer on Windows not verifying access permissions when a custom installation directory is used. If the directory allows modification by unauthorized users, an attacker could place a malicious DLL to hijack the agent's loading process. It is recommended to check directory permissions and restrict write access to trusted users only.
Azərbaycanca: CVE-2026-59781 Zabbix Agent-in Windows-da fərdi qovluğa quraşdırılması zamanı quraşdırıcının icazələri yoxlamaması ilə bağlıdır. Əgər hədəf qovluq icazəsiz istifadəçilər tərəfindən dəyişdirilə bilərsə, hücumçu zərərli DLL yerləşdirərək agentin yüklənməsini ələ keçirə bilər. Quraşdırma qovluğunun təhlükəsizlik icazələrini yoxlamaq və yalnız etibarlı istifadəçilərə yazma hüququ vermək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-732
FAQ2
What misconfiguration causes the CVE-2026-59781 vulnerability during Zabbix Agent installation on Windows?
The vulnerability arises because the Zabbix Agent installer does not verify the security permissions of a custom installation directory, which could allow unauthorized users to modify the target directory.
How can an attacker exploit CVE-2026-59781?
An attacker could place a malicious DLL into the installation directory if it has unauthorized write access, thereby hijacking the agent's loading process.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.