Bug 2417984 (CVE-2025-27232)

Summary: CVE-2025-27232 zabbix: Zabbix: Authenticated Super Admin can read arbitrary files via oauth.authorize action
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedKeywords: Security
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in Zabbix. This vulnerability allows an authenticated Zabbix Super Admin to read arbitrary files from the webserver via exploiting the oauth.authorize action, leading to potential confidentiality loss.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2421502, 2421503, 2421504, 2421505, 2421507    
Bug Blocks:    

Description OSIDB Bzimport 2025-12-01 13:01:24 UTC
An authenticated Zabbix Super Admin can exploit the oauth.authorize action to read arbitrary files from the webserver leading to potential confidentiality loss.