#VU116614 Improper access control in Zabbix - CVE-2025-49641
Published: October 6, 2025
Zabbix
Zabbix
Description
The vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions for the problem.view.refresh action. A remote user with no permission to the "Monitoring -> Problems" view can call the problem.view.refresh action and therefore still retrieve a list of active problems.