CVE-2026-23925 PUBLISHED

Unauthorized host creation via configuration.import API by low-privilege user with write permissions

Assigner: Zabbix
Reserved: 19.01.2026 Published: 06.03.2026 Updated: 06.03.2026

An authenticated Zabbix user (User role) with template/host write permissions is able to create objects via the configuration.import API. This can lead to confidentiality loss by creating unauthorized hosts. Note that the User role is normally not sufficient to create and edit templates/hosts even with write permissions.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:L/SC:H/SI:N/SA:L
CVSS Score: 5.1

Product Status

Vendor Zabbix
Product Zabbix
Versions Default: unknown
  • affected from 6.0.0 to 6.0.40 (incl.)
  • affected from 7.0.0 to 7.0.17 (incl.)
  • affected from 7.4.0 to 7.4.1 (incl.)

Affected Configurations

Low-privilege user invoking configuration.import to perform unauthorized object creation.

Workarounds

Remove template and host write permissions for non-admin users.

Solutions

Update the affected components to their respective fixed versions.

References

Problem Types

  • CWE-863: Incorrect Authorization CWE

Impacts

  • CAPEC-122: Privilege Abuse