CVE-2026-59787
Received
Received - Intake
Zabbix SNMP Trap Injection Leading to Data Integrity Loss
Vulnerability report for CVE-2026-59787, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-05
Last updated on: 2026-10-05
Assigner: Zabbix
Description
Description
The Perl SNMP trap receiver script shipped with Zabbix does not properly neutralize the ZBXTRAP record delimiter in trap content. This means someone able to send SNMP traps can inject a record targeting another host, resulting in a loss of integrity.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| Zabbix | Zabbix | 6.0.0 |
| Zabbix | Zabbix | 7.0.0 |
| Zabbix | Zabbix | 7.4.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-143 | The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as record delimiters when they are sent to a downstream component. |