Unrated severityNVD Advisory· Published Dec 1, 2025· Updated Dec 1, 2025
Frontend arbitrary file read in oauth.authorize action
CVE-2025-27232
Description
An authenticated Zabbix Super Admin can exploit the oauth.authorize action to read arbitrary files from the webserver leading to potential confidentiality loss.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.