LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2022-23131: Zabbix Frontend Authentication Bypass Vulnerability

RBRecent Breaches Vulnerability Intelligence·Feb 22, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Mar 8, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2022-23131 to its Known Exploited Vulnerabilities catalog on Feb 22, 2022, with a federal patch deadline of Mar 8, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML.

CVE-2022-23131 is an authentication bypass vulnerability in the Zabbix Frontend that can allow an attacker to take over a Zabbix instance when SAML authentication is configured. It stems from unsafe client-side session storage. For organizations running Zabbix as a monitoring platform, successful abuse can mean full control of the frontend and the visibility and management capabilities it provides, so timely identification and remediation matter.

Public detail is limited to the CISA description and the stated weakness; confirm exact affected configurations, fixed releases, and deployment notes against the vendor advisory before acting.

How it works

The vulnerability is classified as CWE-290 (Authentication Bypass by Spoofing). In this case, the Zabbix Frontend stores session-related material in a way that is unsafe on the client side when SAML is in use. An attacker who can interact with that client-side storage can spoof or manipulate session state so the frontend treats them as an authenticated user, bypassing normal login controls.

At a high level, the abuse path is: the frontend trusts client-held session data that should not be solely relied upon for authentication decisions; the attacker supplies or alters that data to obtain a valid session and thereby gain instance-level access. Exact request flows, parameters, or exploit steps are not provided in the given facts and must not be assumed—treat any public proof-of-concept claims cautiously and validate behavior only in authorized test environments against the vendor’s description.

Am I affected? How to find it in your systems

Zabbix Frontend is the web interface component of the Zabbix monitoring stack. It commonly runs on internal or DMZ web servers, often behind reverse proxies, and is used by operations and security teams to view metrics, alerts, and host configuration. Instances that have SAML authentication configured are the ones called out in the CISA summary.

How to remediate

Patch first. Apply the updates published by the Zabbix vendor for the Frontend as instructed in their advisory and in line with the CISA required action: “Apply updates per vendor instructions.” Schedule the update through your normal change process, verify the service starts cleanly, and re-validate SAML login and session behavior after the upgrade.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls focused on this authentication-bypass class and on SAML-enabled frontends.

If your data may have been exposed

Actively exploited authentication-bypass flaws can lead to full instance takeover and subsequent data access or lateral movement. Known ransomware use is not documented for this CVE in the provided facts. If you have reason to believe your Zabbix Frontend was compromised, follow your incident-response process: isolate the host, preserve logs, rotate credentials and secrets, and assess what monitoring data or credentials the instance could reach. As a simple additional check, you can run a free exposure scan of your email addresses against known breach datasets to see whether associated accounts appear in prior breaches.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedZabbix · Frontend
WeaknessCWE-290
Added to CISA KEVFeb 22, 2022
Federal patch deadlineMar 8, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities