An authenticated Zabbix user (User role) with template/host write permissions is able to create objects via the configuration.import API. This can lead to confidentiality loss by creating unauthorized hosts. Note that the User role is normally not sufficient to create and edit templates/hosts even with write permissions.
CVSS
No CVSS.
References
| Link | Resource |
|---|---|
| https://support.zabbix.com/browse/ZBX-27567 |
Configurations
No configuration.
History
06 Mar 2026, 09:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-06 09:15
Updated : 2026-03-09 13:35
NVD link : CVE-2026-23925
Mitre link : CVE-2026-23925
CVE.ORG link : CVE-2026-23925
JSON object : View
Products Affected
No product.
CWE
CWE-863
Incorrect Authorization
