CVE-2025-49641

Publication date 3 October 2025

Last updated 8 October 2025


Ubuntu priority

Description

A regular Zabbix user with no permission to the Monitoring -> Problems view is still able to call the problem.view.refresh action and therefore still retrieve a list of active problems.

Status

Package Ubuntu Release Status
zabbix 25.10 questing
Needs evaluation
25.04 plucky
Needs evaluation
24.04 LTS noble Not in release
22.04 LTS jammy
Needs evaluation
20.04 LTS focal
Needs evaluation
18.04 LTS bionic
Needs evaluation
16.04 LTS xenial
Needs evaluation
14.04 LTS trusty
Needs evaluation