CVE-2025-27232
EUVD-2025-19998701.12.2025, 13:16
An authenticated Zabbix Super Admin can exploit the oauth.authorize action to read arbitrary files from the webserver leading to potential confidentiality loss.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| zabbix | frontend | 7.4.0 ≤ 𝑥 < 7.4.3 |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| zabbix | zabbix | 7.4.0 ≤ 𝑥 ≤ 7.4.2 | CNA |
Ubuntu Releases