Zabbix LDAP Bind Password Leakage Vulnerability

Vulnerability

A vulnerability exists in Zabbix's handling of LDAP 'Bind password' values. Once saved, the password cannot be read; however, a Super Admin can leak it by changing the LDAP 'Host' to a malicious server. This issue is present in Zabbix versions 6.0.0 through 6.0.40, 7.0.0 through 7.0.17, 7.2.0 through 7.2.11, and 7.4.0 through 7.4.1. To address this vulnerability, the 'Bind password' value is now reset whenever the 'Host' is changed.

Impact

Exploitation of this vulnerability allows a Zabbix Super Admin to leak the LDAP 'Bind password' value.

Remediation

Users can update to Zabbix versions 6.0.41, 7.0.18, 7.2.12, or 7.4.2 to address this vulnerability.

Added: Oct 3, 2025, 12:47 PM
Updated: Oct 3, 2025, 12:47 PM

Vulnerability Rating

Custom Algorithm
spread
6.2
impact
2.5
exploitability
4.4
remediation
7.7
relevance
0.6
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.