CVE-2025-27238: API hostprototype.get lists data to users with insufficient authorization.
Published Sep 12, 2025
·Updated
Due to a bug in Zabbix API, the hostprototype.get method lists all host prototypes to users that do not have any user groups assigned to them.
Affected Software
3 affected components
Zabbix Zabbix API
Zabbix Zabbix>=7.0.0<7.0.14
Zabbix Zabbix>=7.2.0<7.2.8
Remediation
Information
Update the affected components to their respective fixed versions.
Event History
Sep 12, 2025
CVE Published
via MITRE·10:33 AM
Data Sourced
via MITRE·10:33 AM
RemedyDescriptionWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-27238?
CVE-2025-27238 is classified as a medium severity vulnerability affecting the Zabbix API.
2
How do I fix CVE-2025-27238?
To mitigate CVE-2025-27238, ensure that user permissions are properly configured to restrict access to the hostprototype.get method.
3
What systems are affected by CVE-2025-27238?
CVE-2025-27238 affects the Zabbix API, specifically the hostprototype.get method.
4
What is the impact of CVE-2025-27238?
CVE-2025-27238 allows unauthorized users to access and list all host prototypes, which could lead to information disclosure.
5
Is there a workaround for CVE-2025-27238 until a patch is available?
A potential workaround for CVE-2025-27238 is to temporarily limit access to the Zabbix API for unauthorized users.