The bug description Link to heading
CVE Record : https://www.zabbix.com/security_advisories?query=CVE-2025-27236.
A regular Zabbix user can search other users in their user group via Zabbix API by select fields the user does not have access to view. This allows data-mining some field values the user does not have access to.
In collab with ExoD