Back to search
CVE-2025-49641
Published: Oct 3, 2025
Modified: Oct 3, 2025
PUBLISHED
Description
A regular Zabbix user with no permission to the Monitoring -> Problems view is still able to call the problem.view.refresh action and therefore still retrieve a list of active problems.
| Vendor | Product | Versions |
|---|---|---|
Zabbix | Zabbix | affected 6.0.0 - <= 6.0.40affected 7.0.0 - <= 7.0.17affected 7.2.0 - <= 7.2.11affected 7.4.0 - <= 7.4.1 |
Weaknesses (CWE)
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now