An authenticated user with API access (e.g.: user with default User role), more specifically a user with access to the user.update API endpoint is enough to be able to add themselves to any group (e.g.: Zabbix Administrators), except to groups that are disabled or having restricted GUI access.
[
{
"source": "https://github.com/zabbix/zabbix/commit/e05e6ba9dca6bac63179965db2d95b9e32a11b1b",
"signature_version": "v1",
"deprecated": false,
"id": "CVE-2024-36467-42185414",
"target": {
"file": "src/zabbix_java/src/com/zabbix/gateway/GeneralInformation.java"
},
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"42377719247154798294649350857211914722",
"277301446743689282564066719793421861949",
"84053493762398819857165875037492472417",
"134573353912766890848741256532153642229",
"177130751556011487463321449951885775840",
"255221815652418511241443785427600625788"
]
}
}
]