CVE-2025-27236
03.10.2025, 12:15
A regular Zabbix user can search other users in their user group via Zabbix API by select fields the user does not have access to view. This allows data-mining some field values the user does not have access to.Enginsight
| Vendor | Product | Version |
|---|---|---|
| zabbix | zabbix | 6.0.38 ≤ 𝑥 < 6.0.41 |
| zabbix | zabbix | 7.0.9 ≤ 𝑥 < 7.0.17 |
| zabbix | zabbix | 7.2.3 ≤ 𝑥 < 7.2.11 |
| zabbix | zabbix | 7.4.0 |
𝑥
= Vulnerable software versions