CVE-2026-59787
Received Received - Intake

Zabbix SNMP Trap Injection Leading to Data Integrity Loss

Vulnerability report for CVE-2026-59787, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: Zabbix

Description

The Perl SNMP trap receiver script shipped with Zabbix does not properly neutralize the ZBXTRAP record delimiter in trap content. This means someone able to send SNMP traps can inject a record targeting another host, resulting in a loss of integrity.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
Zabbix Zabbix 6.0.0
Zabbix Zabbix 7.0.0
Zabbix Zabbix 7.4.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-143 The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as record delimiters when they are sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Zabbix SNMP trap receiver script fails to properly sanitize the ZBXTRAP record delimiter in SNMP trap content. This allows an attacker who can send SNMP traps to inject crafted records that target other hosts, compromising data integrity.

Detection Guidance

This vulnerability involves improper handling of SNMP trap content in Zabbix. Detection requires monitoring SNMP traffic for malformed traps or unexpected record delimiters. Check Zabbix server logs for unusual trap processing errors or integrity violations. Inspect network traffic for SNMP traps containing ZBXTRAP delimiters targeting multiple hosts.

Impact Analysis

An attacker could manipulate SNMP traps to alter or redirect data to unintended systems, leading to incorrect monitoring data, potential service disruptions, or unauthorized access to sensitive information.

Compliance Impact

This vulnerability could violate integrity requirements in GDPR and HIPAA by allowing unauthorized data modification. Compliance may be impacted if monitoring data integrity is compromised.

Mitigation Strategies

Update Zabbix to the latest version that patches this vulnerability. Monitor SNMP trap logs for unusual activity or unexpected host targeting. Restrict SNMP trap sender permissions to trusted sources only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-59787. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart