CVE-2026-59787 PUBLISHED

SNMP trap injection in zabbix_trap_receiver.pl

Assigner: Zabbix
Reserved: 07.07.2026 Published: 05.10.2026 Updated: 05.10.2026

The Perl SNMP trap receiver script shipped with Zabbix does not properly neutralize the ZBXTRAP record delimiter in trap content. This means someone able to send SNMP traps can inject a record targeting another host, resulting in a loss of integrity.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
CVSS Score: 5.3

Product Status

Vendor Zabbix
Product Zabbix
Versions Default: unknown
  • affected from 6.0.0 to 6.0.47 (incl.)
  • affected from 7.0.0 to 7.0.28 (incl.)
  • affected from 7.4.0 to 7.4.12 (incl.)

Affected Configurations

Attacker sending crafted SNMP trap payloads to the trap receiver.

Solutions

Update the affected components and replace the deployed zabbix_trap_receiver.pl with the fixed version.

Credits

  • Zabbix wants to thank stoun for submitting this report on the HackerOne bug bounty platform. reporter

References

Problem Types

  • CWE-143: Improper Neutralization of Record Delimiters CWE

Impacts

  • CAPEC-153: Input Data Manipulation