Information disclosure in Zabbix - CVE-2025-27231

 

Information disclosure in Zabbix - CVE-2025-27231

Published: October 6, 2025


Vulnerability identifier: #VU116615
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N]
CVE-ID: CVE-2025-27231
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to gain access to sensitive information.

The vulnerability exists due to a logic error when updating LDAP configuration. A remote authenticated administrator can change the 'Host' field of the LDAP server to an arbitrary value and recover the previously saved password for the previous connection. 


Affected software

Zabbix

How to mitigate CVE-2025-27231

Install updates from vendor's website.

Zabbix - addressed in versions 6.0.41, 7.0.18, 7.2.12, 7.4.2

External References

Related Security Bulletins