CVE-2026-23925Disclosure(zabbix / zabbix)

LOWCVSS 8.1 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

An authenticated Zabbix user (User role) with template/host write permissions is able to create objects via the configuration.import API. This can lead to confidentiality loss by creating unauthorized hosts. Note that the User role is normally not sufficient to create and edit templates/hosts even with write permissions.

0.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • zabbix

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
zabbix

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-06: 3Technical Details · 2026-03-06: 303-06
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-23925 An authenticated Zabbix user (User role) with template/host write permissions is able to create objects via the configuration.import API. This can lead to confidentia… https://www.cve.org/CVERecord?id=CVE-2026-23925

    Post summary

    The statement announces CVE-2026-23925, noting that authenticated Zabbix users with template/host write permissions can create objects through the configuration.import API.

    00000135
    56.6K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-23925 - Unauthorized host creation via configuration.import API by low-privilege user with write permissions Intel Report: https://ift.tt/7BikWGN

    Post summary

    The advisory alerts on CVE-2026-23925, noting that low-privilege users with write permissions can create hosts via the configuration.import API. No PoC, exploit, patch, or active exploitation details are provided.

    0000035
    343 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-23925 Zabbix Configuration Import API Unauthorized Host Creation Vulnerability https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-23925

    Post summary

    The content is a simple vulnerability disclosure for CVE-2026-23925, mentioning an unauthorized host creation flaw via Zabbix's configuration import API.

    0000055
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appzabbixzabbix---

Explore more