CVE 5.1 MEDIUM

Insufficient permission check for the problem.view.refresh action_CVE-2025-49641

5.1 / 10
MEDIUM
CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

Description

A regular Zabbix user with no permission to the Monitoring -> Problems view is still able to call the problem.view.refresh action and therefore still retrieve a list of active problems.

Basic Information

ID CVE-2025-49641
Source Zabbix
Published Oct 3, 2025 at 11:29

Affected Product

Vendor Zabbix
Product Zabbix
Version 6.0.0
Affected Versions Zabbix Zabbix 6.0.0
Zabbix Zabbix 7.0.0
Zabbix Zabbix 7.2.0
Zabbix Zabbix 7.4.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.