A regular Zabbix user can search other users in their user group via Zabbix API by select fields the user does not have access to view. This allows data-mining some field values the user does not have access to.
[
{
"signature_version": "v1",
"deprecated": false,
"signature_type": "Line",
"digest": {
"line_hashes": [
"312614962226865881994625562760193464620",
"243857299040616033543277099011018562380",
"115047375198210276379139485775260446152",
"131652300589887294827463178296045152164",
"24451493220463986177515936334733341608",
"22616098638544051939022181165573400285"
],
"threshold": 0.9
},
"id": "CVE-2025-27236-eda0a3f5",
"target": {
"file": "src/zabbix_java/src/com/zabbix/gateway/GeneralInformation.java"
},
"source": "https://github.com/zabbix/zabbix/commit/40573c111594a4a96aee6c4670e4df252d278bb7"
}
]