Information Disclosure Vulnerability in Zabbix by Zabbix SIA
CVE-2025-49641

5.1MEDIUM

Key Information:

Vendor

Zabbix

Status
Vendor
CVE Published:
3 October 2025

What is CVE-2025-49641?

A Zabbix user without necessary permissions can exploit a flaw to invoke the problem.view.refresh action, granting access to a list of active problems. This oversight can lead to unauthorized visibility into sensitive monitoring data.

Affected Version(s)

Zabbix 6.0.0 <= 6.0.40

Zabbix 7.0.0 <= 7.0.17

Zabbix 7.2.0 <= 7.2.11

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Zabbix wants to thank Y. Kahveci for finding and reporting this issue.
.
CVE-2025-49641 : Information Disclosure Vulnerability in Zabbix by Zabbix SIA