CVE-2025-27236: Zabbix

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

A regular Zabbix user can search other users in their user group via Zabbix API by select fields the user does not have access to view. This allows data-mining some field values the user does not have access to.

Affected products

  • Zabbix Zabbix: from 6.0.38, before 6.0.41 (fixed in 6.0.41); from 7.0.9, before 7.0.17 (fixed in 7.0.17); from 7.2.3, before 7.2.11 (fixed in 7.2.11); version 7.4.0 only

Published 2025-10-03. Last modified 2026-06-17.