MEDIUM
Frontend arbitrary file read in oauth.authorize action
Published Dec 1, 2025
6.8
MEDIUMCVSS 4.0
EPSS 0.29%
Description
An authenticated Zabbix Super Admin can exploit the oauth.authorize action to read arbitrary files from the webserver leading to potential confidentiality loss.
Affected products
-
- Version 7.4.0StatusaffectedConstraints<=7.4.2
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Update the affected components to their respective fixed versions.
Red Hat statement
This vulnerability is rated Moderate for Red Hat as an authenticated Zabbix Super Admin can read arbitrary files from the webserver. This flaw requires high privileges, specifically a Super Admin account, to exploit the oauth.authorize action, leading to potential confidentiality loss within Zabbix deployments in Community Projects.
Weaknesses (1)
References (6)
- https://access.redhat.com/security/cve/CVE-2025-27232 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2417984 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-199987 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-27232
- https://support.zabbix.com/browse/ZBX-27282 Vendor Advisory
- https://www.cve.org/CVERecord?id=CVE-2025-27232
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2025-27232 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2417984 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-199987 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2025-27232 | ||
| https://support.zabbix.com/browse/ZBX-27282 | Vendor Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2025-27232 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Zabbix
Published Dec 1, 2025
Updated Dec 1, 2025
Reserved Feb 20, 2025
Link CVE-2025-27232
CISA Vulnrichment
Updated Dec 1, 2025
ENISA EUVD
EUVD-2025-199987 Assigner Zabbix
Published Dec 1, 2025
Updated Dec 1, 2025
Exploited since n/a
Link EUVD-2025-199987