CVE-2026-23925
Zabbix Server vulnerability analysis and mitigation

Overview

CVE-2026-23925 is an authorization bypass vulnerability in Zabbix that allows an authenticated low-privilege user (User role) with template/host write permissions to create unauthorized objects — including hosts — via the configuration.import API, leading to confidentiality and integrity loss. It was published on March 6, 2026, and affects Zabbix versions 6.0.0–6.0.40, 7.0.0–7.0.17, and 7.4.0–7.4.1. The vulnerability carries a CVSS v3.1 base score of 8.1 (High) and a CVSS v4.0 base score of 5.1 (Medium) (Zabbix Support, Red Hat Bugzilla).

Technical details

The root cause is improper access control (CWE-266: Incorrect Privilege Assignment; CWE-863: Incorrect Authorization) in Zabbix's configuration.import API endpoint. Normally, the User role is insufficient to create or edit templates and hosts even when granted write permissions on those objects; however, the API fails to enforce this restriction, allowing a User-role account with template/host write permissions to invoke configuration.import and create arbitrary host objects. The attack is network-accessible, requires no user interaction, and has low attack complexity, though it does require the attacker to already possess valid credentials and the specific write permissions (Zabbix Support, Red Hat Bugzilla).

Impact

Successful exploitation allows an authenticated low-privilege user to create unauthorized hosts and other configuration objects within Zabbix, bypassing the intended role-based access controls. This results in high confidentiality and integrity impact at the system (subsequent/downstream) scope, as unauthorized hosts could be used to intercept monitoring data, inject malicious configurations, or facilitate lateral movement within monitored infrastructure. Availability is not directly impacted by this vulnerability (Zabbix Support, Red Hat Bugzilla).

Exploitation steps

  1. Obtain credentials: Acquire valid Zabbix credentials for a User-role account that has been granted write permissions on templates or hosts — either through credential theft, phishing, or insider access.
  2. Authenticate to Zabbix API: Send an API authentication request to the Zabbix JSON-RPC endpoint (e.g., POST /api_jsonrpc.php) with the User-role credentials to obtain a valid session token.
  3. Craft a malicious import payload: Prepare a Zabbix XML or JSON configuration export file containing a new host definition with desired properties (e.g., hostname, interfaces, linked templates).
  4. Invoke configuration.import API: Call the configuration.import API method with the crafted payload and the obtained session token, bypassing the normal role-based restriction that would prevent a User-role account from creating hosts.
  5. Verify unauthorized object creation: Confirm that the new host has been created in Zabbix, potentially using it to intercept monitoring data, inject malicious items/triggers, or pivot to monitored systems (Zabbix Support).

Indicators of compromise

  • Logs: Zabbix audit logs showing configuration.import API calls originating from User-role accounts; unexpected host creation events attributed to non-administrative users in the Zabbix audit trail.
  • Network: API requests to /api_jsonrpc.php with method configuration.import from unusual source IPs or at unusual times for low-privilege accounts.
  • Application: Newly created hosts or templates in Zabbix that were not provisioned by administrators; unexpected changes to host group memberships or linked templates.

Mitigation and workarounds

Zabbix has released fixed versions addressing this vulnerability: 6.0.41 (for the 6.0.x branch), 7.0.18 (for the 7.0.x branch), and 7.4.2 (for the 7.4.x branch). Organizations should upgrade to the respective fixed version as the primary remediation. As a workaround, administrators should remove template and host write permissions from all non-administrative (User-role) accounts, and monitor configuration.import API usage for suspicious activity (Zabbix Support).

Community reactions

The vulnerability was reported by Janis Nulle and resolved by the Zabbix Support Team within the same day of disclosure (March 6, 2026). Red Hat tracked the issue via Bugzilla as a medium-severity security response item. No significant broader media coverage or notable researcher commentary beyond standard vulnerability database entries has been identified (Red Hat Bugzilla, Zabbix Support).

Additional resources


SourceThis report was generated using AI

Related Zabbix Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-23928HIGH7.3
  • Zabbix Server logoZabbix Server
  • cpe:2.3:a:zabbix:zabbix
NoNoMay 06, 2026
CVE-2026-23926HIGH7.3
  • Zabbix Server logoZabbix Server
  • cpe:2.3:a:zabbix:zabbix
NoNoMay 06, 2026
CVE-2026-23923MEDIUM6.9
  • Zabbix Server logoZabbix Server
  • cpe:2.3:a:zabbix:zabbix
NoNoMar 24, 2026
CVE-2026-23924MEDIUM6.1
  • Zabbix Server logoZabbix Server
  • cpe:2.3:a:zabbix:zabbix
NoNoMar 24, 2026
CVE-2026-23927MEDIUM5.1
  • Zabbix Server logoZabbix Server
  • zabbix
NoNoMay 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management