#VU116615 Information disclosure in Zabbix - CVE-2025-27231
Published: October 6, 2025
Zabbix
Zabbix
Description
The vulnerability allows a remote user to gain access to sensitive information.
The vulnerability exists due to a logic error when updating LDAP configuration. A remote authenticated administrator can change the 'Host' field of the LDAP server to an arbitrary value and recover the previously saved password for the previous connection.