CVE-2026-59787

The Perl SNMP trap receiver script shipped with Zabbix does not properly neutralize the ZBXTRAP record delimiter in trap content. This means someone able to send SNMP traps can inject a record targeting another host, resulting in a loss of integrity.

Credits

Zabbix wants to thank stoun for submitting this report on the HackerOne bug bounty platform.

References