CVE Database · CVE-2026-23925
CVSS v3.1
N/A
CVSS v4.0
5.1
EPSS
0.26%
Published
Mar 6, 2026
Modified
Mar 9, 2026
Public PoC / Exploit
All weaponized →No public PoC or exploit code indexed for this CVE.
Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
An authenticated Zabbix user (User role) with template/host write permissions is able to create objects via the configuration.import API. This can lead to confidentiality loss by creating unauthorized hosts. Note that the User role is normally not sufficient to create and edit templates/hosts even with write permissions.
Weaknesses (CWE)
References (1)