LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2022-23134: Zabbix Frontend Improper Access Control Vulnerability

RBRecent Breaches Vulnerability Intelligence·Feb 22, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Mar 8, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2022-23134 to its Known Exploited Vulnerabilities catalog on Feb 22, 2022, with a federal patch deadline of Mar 8, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Malicious actors can pass step checks and potentially change the configuration of Zabbix Frontend.

CVE-2022-23134 is an improper access control vulnerability in the Zabbix Frontend. According to CISA, malicious actors can pass step checks and potentially change the configuration of Zabbix Frontend. That matters because Zabbix is commonly used for infrastructure monitoring; unauthorized configuration changes can undermine monitoring integrity, alter alerting, or open paths to further compromise of the monitored environment.

Defenders should treat this as a configuration-access issue on the web frontend and confirm exact impact, fixed releases, and deployment notes against the vendor advisory before acting.

How it works

The weakness is classified as CWE-284 (Improper Access Control). In this class of flaw, the application does not adequately enforce who is allowed to perform sensitive steps or operations. CISA’s summary states that malicious actors can pass step checks and potentially change the configuration of Zabbix Frontend.

At a high level, an attacker who can reach the affected frontend functionality may bypass intended access checks that gate multi-step or privileged configuration actions. Public detail beyond that summary is limited; do not assume unauthenticated access, specific request patterns, or privilege levels unless the vendor advisory confirms them. Abuse would center on reaching the frontend’s configuration-related flows and succeeding at checks that should have blocked the actor, resulting in unauthorized configuration changes rather than a generic remote code execution claim.

Am I affected? How to find it in your systems

Zabbix Frontend is the web UI component of Zabbix monitoring deployments. It typically runs on servers or containers that host the Zabbix web interface, often alongside or in front of the Zabbix server and database, and is exposed to administrators via HTTP/HTTPS—sometimes on internal networks only, sometimes more broadly.

If version or component mapping is unclear, assume possible exposure until you confirm against the vendor advisory.

How to remediate

Patch first. CISA’s required action is to apply updates per vendor instructions. Upgrade Zabbix Frontend to the fixed release(s) named in the official Zabbix advisory for CVE-2022-23134, following your normal change and test process.

If you can't patch immediately

Until the vendor update is applied, reduce exposure with compensating controls aimed at this access-control class of issue.

These steps lower risk but do not replace applying the vendor update.

If your data may have been exposed

Actively exploited vulnerabilities can lead to unauthorized access and follow-on breaches, even when ransomware use is not documented for this CVE. If your Zabbix Frontend may have been reachable and unpatched, investigate for unauthorized configuration changes, review admin and system logs, and follow your incident response process for credential rotation and scope assessment. You can also run a free exposure scan of your email addresses against known breach data to see whether associated accounts appear in public breach corpora while you complete containment and patching.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedZabbix · Frontend
WeaknessCWE-284
Added to CISA KEVFeb 22, 2022
Federal patch deadlineMar 8, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities