
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-23925 is an authorization bypass vulnerability in Zabbix that allows an authenticated low-privilege user (User role) with template/host write permissions to create unauthorized objects — including hosts — via the configuration.import API, leading to confidentiality and integrity loss. It was published on March 6, 2026, and affects Zabbix versions 6.0.0–6.0.40, 7.0.0–7.0.17, and 7.4.0–7.4.1. The vulnerability carries a CVSS v3.1 base score of 8.1 (High) and a CVSS v4.0 base score of 5.1 (Medium) (Zabbix Support, Red Hat Bugzilla).
The root cause is improper access control (CWE-266: Incorrect Privilege Assignment; CWE-863: Incorrect Authorization) in Zabbix's configuration.import API endpoint. Normally, the User role is insufficient to create or edit templates and hosts even when granted write permissions on those objects; however, the API fails to enforce this restriction, allowing a User-role account with template/host write permissions to invoke configuration.import and create arbitrary host objects. The attack is network-accessible, requires no user interaction, and has low attack complexity, though it does require the attacker to already possess valid credentials and the specific write permissions (Zabbix Support, Red Hat Bugzilla).
Successful exploitation allows an authenticated low-privilege user to create unauthorized hosts and other configuration objects within Zabbix, bypassing the intended role-based access controls. This results in high confidentiality and integrity impact at the system (subsequent/downstream) scope, as unauthorized hosts could be used to intercept monitoring data, inject malicious configurations, or facilitate lateral movement within monitored infrastructure. Availability is not directly impacted by this vulnerability (Zabbix Support, Red Hat Bugzilla).
POST /api_jsonrpc.php) with the User-role credentials to obtain a valid session token.configuration.import API method with the crafted payload and the obtained session token, bypassing the normal role-based restriction that would prevent a User-role account from creating hosts.configuration.import API calls originating from User-role accounts; unexpected host creation events attributed to non-administrative users in the Zabbix audit trail./api_jsonrpc.php with method configuration.import from unusual source IPs or at unusual times for low-privilege accounts.Zabbix has released fixed versions addressing this vulnerability: 6.0.41 (for the 6.0.x branch), 7.0.18 (for the 7.0.x branch), and 7.4.2 (for the 7.4.x branch). Organizations should upgrade to the respective fixed version as the primary remediation. As a workaround, administrators should remove template and host write permissions from all non-administrative (User-role) accounts, and monitor configuration.import API usage for suspicious activity (Zabbix Support).
The vulnerability was reported by Janis Nulle and resolved by the Zabbix Support Team within the same day of disclosure (March 6, 2026). Red Hat tracked the issue via Bugzilla as a medium-severity security response item. No significant broader media coverage or notable researcher commentary beyond standard vulnerability database entries has been identified (Red Hat Bugzilla, Zabbix Support).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."