Back to search
CVE-2025-27236
Published: Oct 3, 2025
Modified: Oct 3, 2025
PUBLISHED
Description
A regular Zabbix user can search other users in their user group via Zabbix API by select fields the user does not have access to view. This allows data-mining some field values the user does not have access to.
| Vendor | Product | Versions |
|---|---|---|
Zabbix | Zabbix | affected 6.0.38 - <= 6.0.40affected 7.0.9 - <= 7.0.16affected 7.2.3 - <= 7.2.10affected 7.4.0 - < 7.4.1 |
Weaknesses (CWE)
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now