CVE-2025-27238

Severity CVSS v4.0:
LOW
Type:
CWE-284 Improper Access Control
Publication date:
12/09/2025
Last modified:
08/10/2025

Description

Due to a bug in Zabbix API, the hostprototype.get method lists all host prototypes to users that do not have any user groups assigned to them.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:* 7.0.0 (including) 7.0.14 (excluding)
cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:* 7.2.0 (including) 7.2.8 (excluding)


References to Advisories, Solutions, and Tools