CVE-2025-27232

EUVD-2025-199987
An authenticated Zabbix Super Admin can exploit the oauth.authorize action to read arbitrary files from the webserver leading to potential confidentiality loss.
SSRF
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
ZabbixCNA
4.9 MEDIUM
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 11%
Affected Products (NVD)
VendorProductVersion
zabbixfrontend
7.4.0 ≤
𝑥
< 7.4.3
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
zabbixzabbix
7.4.0 ≤
𝑥
≤ 7.4.2
CNA
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
zabbix
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
dne
plucky
ignored
questing
needs-triage
resolute
needs-triage
trusty
needs-triage
xenial
ignored