Zabbix User Information Disclosure Vulnerability via API

Vulnerability

A user information disclosure vulnerability has been identified in Zabbix versions 6.0.38 through 6.0.40, 7.0.9 through 7.0.16, 7.2.3 through 7.2.10, and 7.4.0. This vulnerability allows regular Zabbix users to search for other users in their group through the Zabbix API. By selecting fields that they do not have permission to view, users can inadvertently data-mine certain field values from other users.

Impact

Exploitation of this vulnerability could lead to unauthorized access to user information that the requester is not permitted to view.

Remediation

Users can update to Zabbix versions 6.0.41, 7.0.17, 7.2.11, or 7.4.1 to address this vulnerability.

Added: Oct 3, 2025, 12:46 PM
Updated: Oct 3, 2025, 12:46 PM

Vulnerability Rating

Custom Algorithm
spread
6.2
impact
0.6
exploitability
4.8
remediation
7.7
relevance
0.6
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.