Executive brief
An authenticated Zabbix Super Admin can exploit the oauth.authorize action to read arbitrary files from the webserver leading to potential confidentiality loss.
Affected products
- Zabbix Frontend
Junglewise Threat Intelligence
CVE-2025-27232 · Severity: medium · CVSS 4.9 · Published 2025-12-01
Technologies: Zabbix Frontend. Vendors: Zabbix.
An authenticated Zabbix Super Admin can exploit the oauth.authorize action to read arbitrary files from the webserver leading to potential confidentiality loss.