Data Exposure Vulnerability in Zabbix API
CVE-2025-27236
2.1LOW
What is CVE-2025-27236?
A vulnerability exists in the Zabbix API that allows a regular user to search for other users within their group and access select fields that should normally be restricted. This can lead to unintended data exposure, as sensitive information may be revealed without adequate authorization checks. This issue highlights the importance of proper access controls and user permissions in API design, particularly for revealing user-related data.
Affected Version(s)
Zabbix 6.0.38 <= 6.0.40
Zabbix 7.0.9 <= 7.0.16
Zabbix 7.2.3 <= 7.2.10
References
CVSS V4
Score:
2.1
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Zabbix wants to thank yannapostrophe and exod for submitting this report on the HackerOne bug bounty platform.