cbcvebase.
CVE-2026-23925
published 2026-03-06

CVE-2026-23925: An authenticated Zabbix user (User role) with template/host write permissions is able to create objects via the configuration.import API. This can lead to…

PriorityP349high8.1CVSS 3.1
AVNACLPRLUINSUCHIHAN
EPSS
0.26%
17.0th percentile
An authenticated Zabbix user (User role) with template/host write permissions is able to create objects via the configuration.import API. This can lead to confidentiality loss by creating unauthorized hosts. Note that the User role is normally not sufficient to create and edit templates/hosts even with write permissions.

Affected

9 ranges
VendorProductVersion rangeFixed in
debianzabbix< zabbix 1:7.0.22+dfsg-1 (forky)zabbix 1:7.0.22+dfsg-1 (forky)
zabbixzabbix>= 0 < 1:7.0.22+dfsg-1~deb13u11:7.0.22+dfsg-1~deb13u1
zabbixzabbix>= 0 < 1:7.0.22+dfsg-11:7.0.22+dfsg-1
zabbixzabbix>= 6.0.0 < 6.0.416.0.41
zabbixzabbix6.0.0 – 6.0.40
zabbixzabbix>= 7.0.0 < 7.0.187.0.18
zabbixzabbix7.0.0 – 7.0.17
zabbixzabbix>= 7.4.0 < 7.4.27.4.2
zabbixzabbix7.4.0 – 7.4.1

CVSS provenance

nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
nvdv4.05.1MEDIUMCVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:L/SC:H/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv5.1MEDIUM
vendor_debian5.1MEDIUM
vendor_redhat5.1MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.