CVE-2022-23131
CWE-290
99.5
RPSRPS range: 0–105; KEV-listed vulnerabilities can receive an exploitation amplifier.
Description
In the case of instances where the SAML SSO authentication is enabled (non-default), session data can be modified by a malicious actor, because a user login stored in the session was not verified. Malicious unauthenticated actor may exploit this issue to escalate privileges and gain admin access to Zabbix Frontend. To perform the attack, SAML authentication is required to be enabled and the actor has to know the username of Zabbix user (or use the guest account, which is disabled by default).
Source: NVD
Signals
- CVSS
- 9.1
- Critical · v3.1
- EPSS
- 95.68%
- Probability of exploitation in the next 30 days (FIRST)
- CISA KEV
- In CISA KEV since Feb 2022
- Fix commit
- No known fix commit
- Sources: MoreFixes, FreshFixes
- Weakness
- CWE-290
- Published
- 13 Jan 2022
- Last modified 30 Oct 2025
How to read these signals: RPS · EPSS · CISA KEV · Data sources
Get this score from the API
curl -H "Authorization: Bearer dsec_live_xxxxxxxx" \
https://api.intelligence.devsecure.io/api/v1/rps/CVE-2022-23131Replace the placeholder with your key. Get a free API key or rank your own CVEs.
Data as of 7 Oct 2026, 05:16 UK time