Improper Neutralization of Special Elements in Output Used by a Downstream Component in Zabbix - CVE-2026-59787
Published: October 5, 2026
Vulnerability details
The vulnerability allows a remote user to modify records for another host.
The vulnerability exists due to improper neutralization of the ZBXTRAP record delimiter in the zabbix_trap_receiver.pl Perl SNMP trap receiver script when processing crafted SNMP trap payloads. A remote user can send a crafted SNMP trap payload to inject a record targeting another host to modify records for another host.
Affected software
Fedora
zabbix6.0
zabbix
zabbix7.0
How to mitigate CVE-2026-59787
zabbix6.0 - update to 6.0.48-1.el8
zabbix - update to 6.0.48-1.el9
zabbix7.0 - addressed in versions 7.0.31-1.el8, 7.0.31-1.el9, 7.0.31-1.el10_2, 7.0.31-1.el10_3, 7.0.31-1.el10_4