Back

MEDIUM

Frontend arbitrary file read in oauth.authorize action

Published Dec 1, 2025

Description

An authenticated Zabbix Super Admin can exploit the oauth.authorize action to read arbitrary files from the webserver leading to potential confidentiality loss.

Affected products

Remediation

Vendor solution

Update the affected components to their respective fixed versions.

Red Hat statement

This vulnerability is rated Moderate for Red Hat as an authenticated Zabbix Super Admin can read arbitrary files from the webserver. This flaw requires high privileges, specifically a Super Admin account, to exploit the oauth.authorize action, leading to potential confidentiality loss within Zabbix deployments in Community Projects.

Weaknesses (1)

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Zabbix
Published Dec 1, 2025
Updated Dec 1, 2025
Reserved Feb 20, 2025
CISA Vulnrichment
Updated Dec 1, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Dec 1, 2025
ENISA EUVD
Assigner Zabbix
Published Dec 1, 2025
Updated Dec 1, 2025
Exploited since n/a
EUVD-2025-199987