An authenticated Zabbix user (User role) with template/host write permissions is able to create objects via the configuration.import API. This can lead to confidentiality loss by creating unauthorized hosts. Note that the User role is normally not sufficient to create and edit templates/hosts even with write permissions.
Metrics
Affected Vendors & Products
References
History
Fri, 06 Mar 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-266 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Fri, 06 Mar 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An authenticated Zabbix user (User role) with template/host write permissions is able to create objects via the configuration.import API. This can lead to confidentiality loss by creating unauthorized hosts. Note that the User role is normally not sufficient to create and edit templates/hosts even with write permissions. | |
| Title | Unauthorized host creation via configuration.import API by low-privilege user with write permissions | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Zabbix
Published: 2026-03-06T08:24:15.428Z
Updated: 2026-03-06T08:24:15.428Z
Reserved: 2026-01-19T14:02:54.327Z
Link: CVE-2026-23925
No data.
Status : Received
Published: 2026-03-06T09:15:56.100
Modified: 2026-03-06T09:15:56.100
Link: CVE-2026-23925