nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-49641 CVE-2025-49641
MEDIUM
Insufficient permission check for the problem.view.refresh action
Record summary
CVE-2025-49641 has a selected CVSS score of 5.1 (medium).
Description
A regular Zabbix user with no permission to the Monitoring -> Problems view is still able to call the problem.view.refresh action and therefore still retrieve a list of active problems.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 3, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
ZabbixBrowse Zabbix / ZabbixDefault status: unknown | CVE List | 6.0.0 to ≤ 6.0.40 | affected |
| 7.0.0 to ≤ 7.0.17 | affected | ||
| 7.2.0 to ≤ 7.2.11 | affected | ||
| 7.4.0 to ≤ 7.4.1 | affected |
References
2support.zabbix.com
https://support.zabbix.com/browse/ZBX-27063