Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2022-23131
Zabbix Frontend — Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N U H H N 9.1 .9568 99.9 YES
AFFECTED
Product Versions Fixed
Frontend 5.4.0 - 5.4.8 – 5.4.9
TIMELINE
Jan 11 Reserved by Zabbix
Jan 13 Published (CNA: Zabbix)
Feb 22 Added to CISA KEV, remediation due 2022-03-08
Description
In the case of instances where the SAML SSO authentication is enabled (non-default), session data can be modified by a malicious actor, because a user login stored in the session was not verified. Malicious unauthenticated actor may exploit this issue to escalate privileges and gain admin access to Zabbix Frontend. To perform the attack, SAML authentication is required to be enabled and the actor has to know the username of Zabbix user (or use the guest account, which is disabled by default).
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| January 11, 2022 | Reserved | Reserved by Zabbix |
| January 13, 2022 | Published | Published (CNA: Zabbix) |
| February 22, 2022 | KEV ADDED | Added to CISA KEV, remediation due 2022-03-08 |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| Zabbix | Frontend | — | 5.4.0 - 5.4.8 | 5.4.9 |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2022-23131 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.