CVE-2026-23925 - Unauthorized host creation via configuration.import API by low-privilege user wi...

CVE-2026-23925 - Unauthorized host creation via configuration.import API by low-privilege user wi...

CVE ID : CVE-2026-23925 Published : March 6, 2026, 9:15 a.m. | 43 minutes ago Description : An authenticated Zabbix user (User role) with template/host write permissions is able to create objects via the configuration.import API. This can lead to confidentiality loss by creating unauthorized hosts. Note that the User role is normally not sufficient to create and edit templates/hosts even with write permissions. Severity: 5.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
MEDIUM
Published
March 6, 2026