Unrated severityNVD Advisory· Published Sep 12, 2025· Updated Sep 15, 2025
API hostprototype.get lists data to users with insufficient authorization.
CVE-2025-27238
Description
Due to a bug in Zabbix API, the hostprototype.get method lists all host prototypes to users that do not have any user groups assigned to them.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.