nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-27232 CVE-2025-27232
MEDIUM
Frontend arbitrary file read in oauth.authorize action
Record summary
CVE-2025-27232 has a selected CVSS score of 6.8 (medium).
Description
An authenticated Zabbix Super Admin can exploit the oauth.authorize action to read arbitrary files from the webserver leading to potential confidentiality loss.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 1, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
ZabbixBrowse Zabbix / ZabbixDefault status: unknown | CVE List | 7.4.0 to ≤ 7.4.2 | affected |
References
2support.zabbix.com
https://support.zabbix.com/browse/ZBX-27282