ExportXMLWordPrintable

    • Type: Defect (Security)
    • Resolution: Fixed
    • Priority: Major
    • None
    • Affects Version/s: None
    • Component/s: Proxy (P), Server (S)
    • None

      CVE ID CVE-2026-59787
      CVSS score 5.3 (Medium)
      CVSS vector CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
      Affected components Server, Proxy
      Summary SNMP trap injection in zabbix_trap_receiver.pl
      Description The Perl SNMP trap receiver script shipped with Zabbix does not properly neutralize the ZBXTRAP record delimiter in trap content. This means someone able to send SNMP traps can inject a record targeting another host, resulting in a loss of integrity.
      Known attack vectors Attacker sending crafted SNMP trap payloads to the trap receiver.
      Affected and fix version/s Affected: 6.0.0 - 6.0.47 → Fixed: 6.0.48
      Affected: 7.0.0 - 7.0.28 → Fixed: 7.0.29
      Affected: 7.4.0 - 7.4.12 → Fixed: 7.4.13
      Mitigation Update the affected components and replace the deployed zabbix_trap_receiver.pl with the fixed version.
      Workarounds -
      Acknowledgements Zabbix wants to thank stoun for submitting this report on the HackerOne bug bounty platform.

            Assignee:
            Zabbix Support Team
            Reporter:
            Janis Nulle
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated:
              Resolved: