CVE-2025-27236
A regular Zabbix user can search other users in their user group via Zabbix API by select fields the user does not have
A regular Zabbix user can search other users in their user group via Zabbix API by select fields the user does not have access to view. This allows data-mining some field values the user does not have access to.
MEDIUM · CVSS 6.5
EPSS 0.00043
Monitor
- No active-exploitation, high-EPSS, or public-exploit signals - routine patching cadence
Sigma rules0
YARA rules0