CVE-2025-27236: User information disclosure via api_jsonrpc.php on method user.get with param search
A regular Zabbix user can search other users in their user group via Zabbix API by select fields the user does not have access to view. This allows data-mining some field values the user does not have access to.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27236?
CVE-2025-27236 is classified as a medium-severity vulnerability due to its potential for data leakage.
How do I fix CVE-2025-27236?
To resolve CVE-2025-27236, update your Zabbix installation to the latest version that includes the security patch addressing this issue.
Who is affected by CVE-2025-27236?
CVE-2025-27236 affects regular Zabbix users who can search for other users within their user group through the Zabbix API.
What impact does CVE-2025-27236 have on user data confidentiality?
CVE-2025-27236 allows users to access and search for fields they do not have permission to view, compromising user data confidentiality.
Is CVE-2025-27236 exploitable without authentication?
CVE-2025-27236 requires authenticated access to a regular Zabbix user account to exploit the vulnerability.