Back

MEDIUM

Unauthorized host creation via configuration.import API by low-privilege user with write permissions

Published Mar 6, 2026

Description

An authenticated Zabbix user (User role) with template/host write permissions is able to create objects via the configuration.import API. This can lead to confidentiality loss by creating unauthorized hosts. Note that the User role is normally not sufficient to create and edit templates/hosts even with write permissions.

Affected products

Remediation

Vendor solution

Update the affected components to their respective fixed versions.

Red Hat statement

This MODERATE impact vulnerability in Zabbix allows an authenticated user with template/host write permissions to create unauthorized hosts via the configuration.import API. This bypasses the normal restrictions for the 'User' role, which typically prevents such users from creating or editing templates and hosts.

Red Hat mitigation

To mitigate this issue, enforce strict role-based access control within Zabbix. Ensure that low-privilege users, especially those with the 'User' role, are not granted template or host write permissions that could be exploited via the `configuration.import` API for unauthorized host creation. Regularly audit user permissions to adhere to the principle of least privilege.

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Zabbix
Published Mar 6, 2026
Updated Mar 9, 2026
Reserved Jan 19, 2026
CISA Vulnrichment
Updated Mar 9, 2026
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Mar 6, 2026
ENISA EUVD
Assigner Zabbix
Published Mar 6, 2026
Updated Mar 9, 2026
Exploited since n/a
EUVD-2026-10026