An authenticated Zabbix user (User role) with template/host write permissions is able to create objects via the configuration.import API. This can lead to confidentiality loss by creating unauthorized hosts. Note that the User role is normally not sufficient to create and edit templates/hosts even with write permissions.
History

Fri, 06 Mar 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-266
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L'}

threat_severity

Moderate


Fri, 06 Mar 2026 08:30:00 +0000

Type Values Removed Values Added
Description An authenticated Zabbix user (User role) with template/host write permissions is able to create objects via the configuration.import API. This can lead to confidentiality loss by creating unauthorized hosts. Note that the User role is normally not sufficient to create and edit templates/hosts even with write permissions.
Title Unauthorized host creation via configuration.import API by low-privilege user with write permissions
Weaknesses CWE-863
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:L/SC:H/SI:N/SA:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Zabbix

Published: 2026-03-06T08:24:15.428Z

Updated: 2026-03-06T08:24:15.428Z

Reserved: 2026-01-19T14:02:54.327Z

Link: CVE-2026-23925

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-03-06T09:15:56.100

Modified: 2026-03-06T09:15:56.100

Link: CVE-2026-23925

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-03-06T08:24:15Z

Links: CVE-2026-23925 - Bugzilla