← Global Threat Landscape

CVE-2022-23131

CWE-290

Critical

99.5

RPS

Description

In the case of instances where the SAML SSO authentication is enabled (non-default), session data can be modified by a malicious actor, because a user login stored in the session was not verified. Malicious unauthenticated actor may exploit this issue to escalate privileges and gain admin access to Zabbix Frontend. To perform the attack, SAML authentication is required to be enabled and the actor has to know the username of Zabbix user (or use the guest account, which is disabled by default).

Source: NVD

Signals

CVSS
9.1
Critical · v3.1
EPSS
95.68%
Probability of exploitation in the next 30 days (FIRST)
CISA KEV
In CISA KEV since Feb 2022
Fix commit
No known fix commit
Sources: MoreFixes, FreshFixes
Weakness
CWE-290
Published
13 Jan 2022
Last modified 30 Oct 2025

How to read these signals: RPS · EPSS · CISA KEV · Data sources

Get this score from the API

curl -H "Authorization: Bearer dsec_live_xxxxxxxx" \
  https://api.intelligence.devsecure.io/api/v1/rps/CVE-2022-23131

Replace the placeholder with your key. Get a free API key or rank your own CVEs.

Data as of 7 Oct 2026, 05:16 UK time

CVE-2022-23131 · RPS 99.5 · DevSecure Intelligence