Summary
Zabbix authenticated the caller but later trusted a separate, attacker-
controlled userid when creating the dashboard-rendering session. A User-role
account could select a Super Admin or other victim, cause a real session to be
created for that identity, and send the victim’s rendered dashboard to an
attacker-controlled email address.
The tracker labels the finding Disclosed rather than Won’t Fix or Under Embargo, so it qualifies under the public no-CVE rule. AI attribution remains self-reported by the Argus operator.
References
Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.