#VU116615 Information disclosure in Zabbix - CVE-2025-27231

 

#VU116615 Information disclosure in Zabbix - CVE-2025-27231

Published: October 6, 2025


Vulnerability identifier: #VU116615
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2025-27231
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Zabbix
Software vendor:
Zabbix

Description

The vulnerability allows a remote user to gain access to sensitive information.

The vulnerability exists due to a logic error when updating LDAP configuration. A remote authenticated administrator can change the 'Host' field of the LDAP server to an arbitrary value and recover the previously saved password for the previous connection. 


Remediation

Install updates from vendor's website.

External links