EXPOSURES › CVE-2022-23131
CVE-2022-23131
HIGH ⌖ ON CISA KEV · EXPLOITEDZabbix frontend authentication bypass via unsafe client-side session storage allows instance takeover when SAML is configured.
An authentication bypass vulnerability in Zabbix's frontend allows attackers to take over instances with SAML configured through unsafe client-side session storage. DIB organizations must ensure Zabbix deployments are patched and SAML configurations are reviewed to prevent unauthorized access. This failure is avoidable through timely patching and secure session management practices.
Shame score — The vulnerability was actively exploited in the wild (KEV) and allowed instance takeover, indicating a significant security oversight that could lead to data breaches or ransomware entry.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML.