nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-23925 CVE-2026-23925
MEDIUM
Unauthorized host creation via configuration.import API by low-privilege user with write permissions
Record summary
CVE-2026-23925 has a selected CVSS score of 5.1 (medium).
Description
An authenticated Zabbix user (User role) with template/host write permissions is able to create objects via the configuration.import API. This can lead to confidentiality loss by creating unauthorized hosts. Note that the User role is normally not sufficient to create and edit templates/hosts even with write permissions.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 9, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
ZabbixBrowse Zabbix / ZabbixDefault status: unknown | CVE List | 6.0.0 to ≤ 6.0.40 | affected |
| 7.0.0 to ≤ 7.0.17 | affected | ||
| 7.4.0 to ≤ 7.4.1 | affected |
References
2support.zabbix.com
https://support.zabbix.com/browse/ZBX-27567