CVE-2025-49641: Zabbix

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

A regular Zabbix user with no permission to the Monitoring -> Problems view is still able to call the problem.view.refresh action and therefore still retrieve a list of active problems.

Affected products

  • Zabbix Zabbix: from 6.0.0, before 6.0.41 (fixed in 6.0.41); from 7.0.0, before 7.0.18 (fixed in 7.0.18); from 7.2.0, before 7.2.12 (fixed in 7.2.12); from 7.4.0, before 7.4.2 (fixed in 7.4.2)

Published 2025-10-03. Last modified 2026-06-17.