CVE Database
/

CVE-2025-27236

Back to search

CVE-2025-27236

Published: Oct 3, 2025

Modified: Oct 3, 2025

PUBLISHED

Description

A regular Zabbix user can search other users in their user group via Zabbix API by select fields the user does not have access to view. This allows data-mining some field values the user does not have access to.

VendorProductVersions

Zabbix

Zabbix

affected
6.0.38 - <= 6.0.40
affected
7.0.9 - <= 7.0.16
affected
7.2.3 - <= 7.2.10
affected
7.4.0 - < 7.4.1

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now