Executive brief
Zabbix is an enterprise-grade monitoring solution used to track the health and performance of IT infrastructure. A security flaw allows low-privileged users to bypass standard restrictions and create unauthorized monitoring hosts or templates via the system's programming interface (API). This could allow an internal user to gain unauthorized access to infrastructure data or disrupt monitoring operations.
Technical details
An incorrect authorization vulnerability (CWE-863) exists in the Zabbix configuration.import API. While the 'User' role is typically restricted from creating or editing templates and hosts even with write permissions, the API fails to properly enforce these role-based access controls during the import process. An authenticated attacker with low-level write permissions can leverage this to create unauthorized objects. The vulnerability affects Zabbix versions 6.0.x, 7.0.x, and 7.4.x. Patches are available in versions 6.0.41, 7.0.18, and 7.4.2.
Affected products
- Zabbix Zabbix 6.0.0 - 6.0.40, 7.0.0 - 7.0.17, 7.4.0 - 7.4.1
Timeline
- 2026-03-06: disclosed
- 2026-03-06: advisory
- 2026-03-18: patched: Resolution confirmed fixed in tracking system