PT-2025-48442 · Zabbix+1 · Zabbix+1

Published

2025-12-01

·

Updated

2026-02-16

·

CVE-2025-27232

CVSS v4.0

6.8

Medium

VectorAV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Zabbix (affected versions not specified)
Description An authenticated Zabbix Super Admin can exploit the oauth.authorize action to read arbitrary files from the webserver, potentially leading to confidentiality loss. The vulnerable action is oauth.authorize.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SSRF

Weakness Enumeration

Related Identifiers

BDU:2025-15874
CVE-2025-27232

Affected Products

Red Os
Zabbix