2.1
/ 10
LOW
CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Description
A regular Zabbix user can search other users in their user group via Zabbix API by select fields the user does not have access to view. This allows data-mining some field values the user does not have access to.
Basic Information
ID
CVE-2025-27236
Source
Zabbix
Published
Oct 3, 2025 at 11:28
Affected Product
Vendor
Zabbix
Product
Zabbix
Version
6.0.38
Affected Versions
Zabbix Zabbix 6.0.38
Zabbix Zabbix 7.0.9
Zabbix Zabbix 7.2.3
Zabbix Zabbix 7.4.0
Zabbix Zabbix 7.0.9
Zabbix Zabbix 7.2.3
Zabbix Zabbix 7.4.0