nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-27238 CVE-2025-27238
LOW
API hostprototype.get lists data to users with insufficient authorization.
Record summary
CVE-2025-27238 has a selected CVSS score of 2.1 (low).
Description
Due to a bug in Zabbix API, the hostprototype.get method lists all host prototypes to users that do not have any user groups assigned to them.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 12, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
ZabbixBrowse Zabbix / ZabbixDefault status: unknown | CVE List | 7.0.0 to ≤ 7.0.13 | affected |
| 7.2.0 to ≤ 7.2.7 | affected |
References
2support.zabbix.com
https://support.zabbix.com/browse/ZBX-26988