---
id: CVE-2026-59787
title: >-
  The Perl SNMP trap receiver script shipped with Zabbix does not properly
  neutralize the ZBXTRAP record delimiter in trap content
summary: >-
  The Perl SNMP trap receiver script shipped with Zabbix does not properly
  neutralize the ZBXTRAP record delimiter in trap content. This means someone
  able to send SNMP traps can inject a record targeting another host, resulting
  in a loss …
severity: medium
cvss: 5.3
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'
cwe:
  - CWE-143
vendor: Zabbix
product: Zabbix
affected:
  - Zabbix >= 6.0.0 <= 6.0.47
  - Zabbix >= 7.0.0 <= 7.0.28
  - Zabbix >= 7.4.0 <= 7.4.12
published: '2026-10-05'
updated: '2026-10-05'
sourceUpdated: '2026-10-05T12:17:10.347'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-59787'
references:
  - url: 'https://support.zabbix.com/browse/ZBX-28197'
    label: security@zabbix.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-10-05T11:23:21.868482Z'
cvssSource: cna
ingestedAt: '2026-10-05T11:18:17.203Z'
---

## Overview

The Perl SNMP trap receiver script shipped with Zabbix does not properly neutralize the ZBXTRAP record delimiter in trap content. This means someone able to send SNMP traps can inject a record targeting another host, resulting in a loss of integrity.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
