CVE-2025-49641: Insufficient permission check for the problem.view.refresh action
A regular Zabbix user with no permission to the Monitoring -> Problems view is still able to call the problem.view.refresh action and therefore still retrieve a list of active problems.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49641?
CVE-2025-49641 is classified as a medium severity vulnerability.
How do I fix CVE-2025-49641?
To fix CVE-2025-49641, ensure that user permissions are properly configured to restrict access to the Monitoring -> Problems view.
Who is affected by CVE-2025-49641?
CVE-2025-49641 affects regular Zabbix users who have not been granted permission to view active problems.
What are the potential impacts of CVE-2025-49641?
The potential impact of CVE-2025-49641 includes unauthorized access to a list of active problems by users without proper permissions.
Is there a workaround for CVE-2025-49641?
A workaround for CVE-2025-49641 is to apply stricter user role management and limit actions that can be called by unauthorized users.