Ad

CVE-2026-23925

MEDIUM CVSS 4.0: 5.1 EPSS 0.01%
Updated Mar 06, 2026
Zabbix
Parameter Value
CVSS 5.1 (MEDIUM)
Type CWE-863 (Incorrect Authorization)
Vendor Zabbix
Public PoC No

An authenticated Zabbix user (User role) with template/host write permissions is able to create objects via the configuration.import API. This can lead to confidentiality loss by creating unauthorized hosts. Note that the User role is normally not sufficient to create and edit templates/hosts even with write permissions.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Attack Requirements
Present
Additional conditions required
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
None
No data leak
Integrity
Low
Partial data modification
Availability
Low
Partial disruption

CVSS Vector v4.0

Related Vulnerabilities