Vulnerabilities
Vulnerable Software
Zabbix:  >> Zabbix  >> 7.0.10  Security Vulnerabilities
A regular Zabbix user with no permission to the Monitoring -> Problems view is still able to call the problem.view.refresh action and therefore still retrieve a list of active problems.
CVSS Score
4.3
EPSS Score
0.001
Published
2025-10-03
The LDAP 'Bind password' value cannot be read after saving, but a Super Admin account can leak it by changing LDAP 'Host' to a rogue LDAP server. To mitigate this, the 'Bind password' value is now reset on 'Host' change.
CVSS Score
4.9
EPSS Score
0.0
Published
2025-10-03
A regular Zabbix user can search other users in their user group via Zabbix API by select fields the user does not have access to view. This allows data-mining some field values the user does not have access to.
CVSS Score
6.5
EPSS Score
0.001
Published
2025-10-03
Due to a bug in Zabbix API, the hostprototype.get method lists all host prototypes to users that do not have any user groups assigned to them.
CVSS Score
3.5
EPSS Score
0.0
Published
2025-09-12


Contact Us

Shodan ® - All rights reserved