CVE-2026-23925
published 2026-03-06CVE-2026-23925: An authenticated Zabbix user (User role) with template/host write permissions is able to create objects via the configuration.import API. This can lead to…
PriorityP349high8.1CVSS 3.1
AVNACLPRLUINSUCHIHAN
EPSS
0.26%
17.0th percentile
An authenticated Zabbix user (User role) with template/host write permissions is able to create objects via the configuration.import API. This can lead to confidentiality loss by creating unauthorized hosts. Note that the User role is normally not sufficient to create and edit templates/hosts even with write permissions.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | zabbix | < zabbix 1:7.0.22+dfsg-1 (forky) | zabbix 1:7.0.22+dfsg-1 (forky) |
| zabbix | zabbix | >= 0 < 1:7.0.22+dfsg-1~deb13u1 | 1:7.0.22+dfsg-1~deb13u1 |
| zabbix | zabbix | >= 0 < 1:7.0.22+dfsg-1 | 1:7.0.22+dfsg-1 |
| zabbix | zabbix | >= 6.0.0 < 6.0.41 | 6.0.41 |
| zabbix | zabbix | 6.0.0 – 6.0.40 | — |
| zabbix | zabbix | >= 7.0.0 < 7.0.18 | 7.0.18 |
| zabbix | zabbix | 7.0.0 – 7.0.17 | — |
| zabbix | zabbix | >= 7.4.0 < 7.4.2 | 7.4.2 |
| zabbix | zabbix | 7.4.0 – 7.4.1 | — |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
nvdv4.05.1MEDIUMCVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:L/SC:H/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv5.1MEDIUM
vendor_debian5.1MEDIUM
vendor_redhat5.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2026-23925: An authenticated Zabbix user (User role) with template/host write permissions is able to create objects via the configuration
osv·2026-03-06·CVSS 5.1
CVE-2026-23925 [MEDIUM] CVE-2026-23925: An authenticated Zabbix user (User role) with template/host write permissions is able to create objects via the configuration
An authenticated Zabbix user (User role) with template/host write permissions is able to create objects via the configuration.import API. This can lead to confidentiality loss by creating unauthorized hosts. Note that the User role is normally not sufficient to create and edit templates/hosts even with write permissions.
GHSA
GHSA-cv64-6j2c-f8cg: An authenticated Zabbix user (User role) with template/host write permissions is able to create objects via the configuration
ghsa_unreviewed·2026-03-06
CVE-2026-23925 [MEDIUM] CWE-863 GHSA-cv64-6j2c-f8cg: An authenticated Zabbix user (User role) with template/host write permissions is able to create objects via the configuration
An authenticated Zabbix user (User role) with template/host write permissions is able to create objects via the configuration.import API. This can lead to confidentiality loss by creating unauthorized hosts. Note that the User role is normally not sufficient to create and edit templates/hosts even with write permissions.
Red Hat
zabbix: Zabbix: Confidentiality loss via improper access control in configuration.import API
vendor_redhat·2026-03-06·CVSS 5.1
CVE-2026-23925 [MEDIUM] CWE-266 zabbix: Zabbix: Confidentiality loss via improper access control in configuration.import API
zabbix: Zabbix: Confidentiality loss via improper access control in configuration.import API
An authenticated Zabbix user (User role) with template/host write permissions is able to create objects via the configuration.import API. This can lead to confidentiality loss by creating unauthorized hosts. Note that the User role is normally not sufficient to create and edit templates/hosts even with write permissions.
A flaw was found in Zabbix. An authenticated user with the 'User' role, who also possesses write permissions for templates or hosts, can exploit the `configuration.import` API. This allows them to create unauthorized objects, such as hosts, which can lead to a loss of confidentiality within the system.
Statement: This MODERATE impact vulnerability in Zabbix allows an authenticat
Debian
CVE-2026-23925: zabbix - An authenticated Zabbix user (User role) with template/host write permissions is...
vendor_debian·2026·CVSS 5.1
CVE-2026-23925 [MEDIUM] CVE-2026-23925: zabbix - An authenticated Zabbix user (User role) with template/host write permissions is...
An authenticated Zabbix user (User role) with template/host write permissions is able to create objects via the configuration.import API. This can lead to confidentiality loss by creating unauthorized hosts. Note that the User role is normally not sufficient to create and edit templates/hosts even with write permissions.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1:7.0.22+dfsg-1)
sid: resolved (fixed in 1:7.0.22+dfsg-1)
trixie: resolved (fixed in 1:7.0.22+dfsg-1~deb13u1)
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-23925 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.1
CVE-2026-23925 [HIGH] CVE-2026-23925 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-23925 :
Zabbix Server vulnerability analysis and mitigation
An authenticated Zabbix user (User role) with template/host write permissions is able to create objects via the configuration.import API. This can lead to confidentiality loss by creating unauthorized hosts. Note that the User role is normally not sufficient to create and edit templates/hosts even with write permissions.
Source : NVD
## 5.1
Score
Published March 6, 2026
Severity MEDIUM
CNA Score 5.1
Affected Technologies
Zabbix Server
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
zabbix
cpe:2.3:a:zabbix:zabbix
Sources
NVD
Bugzilla
CVE-2026-23925 zabbix: Zabbix: Confidentiality loss via improper access control in configuration.import API [epel-all]
bugzilla·2026-03-06·CVSS 8.1
CVE-2026-23925 [HIGH] CVE-2026-23925 zabbix: Zabbix: Confidentiality loss via improper access control in configuration.import API [epel-all]
CVE-2026-23925 zabbix: Zabbix: Confidentiality loss via improper access control in configuration.import API [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
2026-03-06
Published