5.1
/ 10
MEDIUM
CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Description
A regular Zabbix user with no permission to the Monitoring -> Problems view is still able to call the problem.view.refresh action and therefore still retrieve a list of active problems.
Basic Information
ID
CVE-2025-49641
Source
Zabbix
Published
Oct 3, 2025 at 11:29
Affected Product
Vendor
Zabbix
Product
Zabbix
Version
6.0.0
Affected Versions
Zabbix Zabbix 6.0.0
Zabbix Zabbix 7.0.0
Zabbix Zabbix 7.2.0
Zabbix Zabbix 7.4.0
Zabbix Zabbix 7.0.0
Zabbix Zabbix 7.2.0
Zabbix Zabbix 7.4.0