Zabbix Frontend Arbitrary File Read Vulnerability in OAuth Authorization Action

Vulnerability

A vulnerability allowing authenticated Zabbix Super Admins to read arbitrary files from the web server has been identified. This issue arises in the Zabbix Frontend within versions 7.4.0 to 7.4.2, through the OAuth authorization action. Exploitation of this vulnerability could lead to a potential loss of confidentiality.

Impact

Exploitation of this vulnerability could result in unauthorized access to sensitive files on the web server, leading to a potential confidentiality breach.

Remediation

Users can update to Zabbix version 7.4.3 to address this vulnerability.

Added: Dec 1, 2025, 1:17 PM
Updated: Dec 1, 2025, 3:52 PM

Vulnerability Rating

Custom Algorithm
spread
6.2
impact
2.5
exploitability
4.8
remediation
7.7
relevance
1.2
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.