Junglewise Threat Intelligence

CVE-2026-59781: Zabbix Agent Windows installer DLL sideloading in insecure directory

CVE-2026-59781 · Severity: high · CVSS 7.8 · Published 2026-08-18

Vendors: Zabbix.

Executive brief

Zabbix Agent is a monitoring agent that collects system metrics for the Zabbix platform. When installed on Windows, the installer failed to validate that custom installation directories had secure file permissions, allowing attackers with local write access to place malicious DLL files that could be loaded by the application, potentially enabling code execution and system compromise.

Technical details

The vulnerability is a DLL sideloading issue caused by improper validation of custom installation directory permissions during the Windows installer process. An attacker with local write access to an insecure installation directory could place a malicious DLL that would be loaded by Zabbix Agent due to the Windows DLL search order precedence. The attack requires local file write access to the installation directory and user interaction to trigger application startup. Zabbix has patched the issue by hardening the installer to detect unsafe permissions and require explicit user confirmation before proceeding with installation in such locations. Fixed versions are 7.4.13+, 7.0.29+, and 6.0.48+.

Affected products

  • Zabbix Agent 6.0.0-6.0.47, 7.0.0-7.0.28, 7.4.0-7.4.12

Timeline

  • 2026-08-18: disclosed
  • 2026-08-18: patched: Fixed in 7.4.13, 7.0.29, 6.0.48

References