Due to a bug in Zabbix API, the hostprototype.get method lists all host prototypes to users that do not have any user groups assigned to them.
Fixes

Solution

Update the affected components to their respective fixed versions.


Workaround

Make sure there are no Zabbix users without a user group.

History

Fri, 12 Sep 2025 12:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 12 Sep 2025 10:45:00 +0000

Type Values Removed Values Added
Description Due to a bug in Zabbix API, the hostprototype.get method lists all host prototypes to users that do not have any user groups assigned to them.
Title API hostprototype.get lists data to users with insufficient authorization.
References
Metrics cvssV4_0

{'score': 2.1, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Zabbix

Published:

Updated: 2025-09-12T11:54:36.535Z

Reserved: 2025-02-20T11:40:38.480Z

Link: CVE-2025-27238

cve-icon Vulnrichment

Updated: 2025-09-12T11:54:32.704Z

cve-icon NVD

Status : Received

Published: 2025-09-12T11:15:31.517

Modified: 2025-09-12T11:15:31.517

Link: CVE-2025-27238

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.