An authenticated Zabbix user (User role) with template/host write permissions is able to create objects via the configuration.import API. This can lead to confidentiality loss by creating unauthorized hosts. Note that the User role is normally not sufficient to create and edit templates/hosts even with write permissions.
Advisories

No advisories yet.

Fixes

Solution

Update the affected components to their respective fixed versions.


Workaround

Remove template and host write permissions for non-admin users.

History

Fri, 06 Mar 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-266
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L'}

threat_severity

Moderate


Fri, 06 Mar 2026 08:30:00 +0000

Type Values Removed Values Added
Description An authenticated Zabbix user (User role) with template/host write permissions is able to create objects via the configuration.import API. This can lead to confidentiality loss by creating unauthorized hosts. Note that the User role is normally not sufficient to create and edit templates/hosts even with write permissions.
Title Unauthorized host creation via configuration.import API by low-privilege user with write permissions
Weaknesses CWE-863
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:L/SC:H/SI:N/SA:L'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Zabbix

Published:

Updated: 2026-03-06T08:24:15.428Z

Reserved: 2026-01-19T14:02:54.327Z

Link: CVE-2026-23925

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-03-06T09:15:56.100

Modified: 2026-03-06T09:15:56.100

Link: CVE-2026-23925

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-03-06T08:24:15Z

Links: CVE-2026-23925 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses