CVE-2025-27238 - API hostprototype.get lists data to users with insufficient authorization.
CVE ID : CVE-2025-27238
Published : Sept. 12, 2025, 11:15 a.m. | 48 minutes ago
Description : Due to a bug in Zabbix API, the hostprototype.get method lists all host prototypes to users that do not have any user groups assigned to them.
Severity: 2.1 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Sept. 12, 2025, 11:15 a.m. | 48 minutes ago
Description : Due to a bug in Zabbix API, the hostprototype.get method lists all host prototypes to users that do not have any user groups assigned to them.
Severity: 2.1 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...