Information Disclosure Vulnerability in Zabbix by Zabbix SIA
CVE-2025-49641
5.1MEDIUM
What is CVE-2025-49641?
A Zabbix user without necessary permissions can exploit a flaw to invoke the problem.view.refresh action, granting access to a list of active problems. This oversight can lead to unauthorized visibility into sensitive monitoring data.
Affected Version(s)
Zabbix 6.0.0 <= 6.0.40
Zabbix 7.0.0 <= 7.0.17
Zabbix 7.2.0 <= 7.2.11
References
CVSS V4
Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Zabbix wants to thank Y. Kahveci for finding and reporting this issue.