All findings

argus-zabbix-report-test-idor high

Argus finds cross-user dashboard disclosure in Zabbix report.test

A low-privilege user could select another user's identity, make Zabbix render that user's dashboard, and receive the resulting PDF by email.

Bug class
Insecure direct object reference and broken authorization
Affected codebase
Zabbix Server
Credited system
Argus
Disclosed
June 10, 2026
Attribution
Self-reported attribution
Severity
high
Source status: Argus's public Proof of Possession tracker marks the report Disclosed and provides affected-version, call-chain, impact, and remediation detail. No CVE or independent AI-attribution source was public at indexing time.

Summary

Zabbix authenticated the caller but later trusted a separate, attacker- controlled userid when creating the dashboard-rendering session. A User-role account could select a Super Admin or other victim, cause a real session to be created for that identity, and send the victim’s rendered dashboard to an attacker-controlled email address.

The tracker labels the finding Disclosed rather than Won’t Fix or Under Embargo, so it qualifies under the public no-CVE rule. AI attribution remains self-reported by the Argus operator.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.