← Back to CVE List
CVE-2026-59787NVD
Vulnerability Summary
The Perl SNMP trap receiver script shipped with Zabbix does not properly neutralize the ZBXTRAP record delimiter in trap content. This means someone able to send SNMP traps can inject a record targeting another host, resulting in a loss of integrity.
CVSS v4.0 Base Metrics — Score 5.3 (MEDIUM)
Attack VectorNetwork
Attack ComplexityLow
Attack RequirementsNone
Privileges RequiredLow
User InteractionNone
Confidentiality (Vulnerable System)None
Integrity (Vulnerable System)Low
Availability (Vulnerable System)None
Confidentiality (Subsequent System)None
Integrity (Subsequent System)None
Availability (Subsequent System)None
Affected & Patched Versions
- Zabbix Zabbix >= 6.0.0 and <= 6.0.47
- Zabbix Zabbix >= 7.0.0 and <= 7.0.28
- Zabbix Zabbix >= 7.4.0 and <= 7.4.12
- Zabbix Zabbix 6.0.47
- Zabbix Zabbix 7.0.28
- Zabbix Zabbix 7.4.12