CVE-2022-23131 is an improper authentication vulnerability in Zabbix Frontend when non-default SAML single sign-on authentication is enabled. The frontend stored a user login value in session data without verifying it, allowing an unauthenticated actor to modify session data and impersonate a selected Zabbix user.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
8 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository is a compact Python exploit toolkit for CVE-2022-23131 affecting Zabbix when SAML SSO is enabled. It is not tied to a major exploit framework. The repository contains four executable Python tools plus a README. The core technique is consistent across all scripts: request the Zabbix base URL to obtain a zbx_session cookie, decode the base64/URL-encoded JSON, forge the saml_data.username_attribute field to impersonate a chosen user (default Admin), then send the forged cookie to /index_sso.php and extract the authenticated session ID from the returned zbx_session cookie. After that, the scripts use the Zabbix JSON-RPC endpoint /api_jsonrpc.php with the recovered session ID as auth. Repository structure and purpose: zabbix_session_exp.py is the original exploit and most feature-rich offensive script. It performs the auth bypass and can optionally launch a Python reverse shell back to an operator-supplied LHOST:LPORT or a bind shell listening on a chosen port on the target. It uses host.get to select a host, script.create to register a temporary command, script.execute to run it, and script.delete for cleanup. zbxcmd.py is a simpler one-shot command runner that executes arbitrary shell commands either on the Zabbix server (execute_on=1) or on a monitored host through the Zabbix agent (execute_on=0), returning stdout/stderr. zbxshell.py wraps the same script execution primitive into an interactive pseudo-shell, maintaining a current working directory client-side and issuing commands through the API without needing a network callback. zbxapi.py is an interactive enumeration utility that abuses the same bypass to browse sensitive Zabbix data via many API methods, including users, hosts, macros, items, scripts, actions, media types, proxies, discovery rules, services, audit logs, and configuration export. Main exploit capabilities: unauthenticated login as arbitrary users; extraction of a valid authenticated session; arbitrary command execution on the Zabbix server; potential lateral movement to monitored hosts via agent execution if remote commands are enabled; interactive shell-like access; reverse shell and bind shell payload delivery; and broad post-authentication enumeration of credentials, macros, inventory, and operational data. The exploit is operational rather than a bare PoC because it includes working payload delivery and cleanup logic, but payload customization is still manual and not framework-driven.
This repository contains a Python exploit script (zabbix_session_exp.py) and a README.md for CVE-2022-23131, a SAML authentication bypass vulnerability in Zabbix. The exploit targets Zabbix servers with SAML SSO enabled. It works by first obtaining a valid 'zbx_session' cookie from the target, decoding and modifying it to inject a chosen username (typically an admin), and then re-encoding and sending it back to the server. If successful, the attacker is logged in as the specified user, bypassing SAML authentication. The script supports testing single targets or a list of targets from a file, and can use a proxy for debugging. Successful logins are recorded in 'found.txt'. The main attack vector is network-based, targeting the Zabbix web interface, specifically the 'index_sso.php' endpoint. The repository is operational, providing a working exploit with a hardcoded payload structure.
This repository provides an exploit for CVE-2022-23131, a critical authentication bypass vulnerability in Zabbix servers with SAML SSO enabled. The exploit consists of a Python script (zabbix_session_exp.py) that forges a zbx_session cookie by manipulating its base64-encoded JSON payload to impersonate any user, typically the Admin. The script can target a single Zabbix server or multiple servers listed in a file, and supports proxying requests for debugging. Successful exploitation results in unauthorized access to the Zabbix dashboard. The repository also includes a Nuclei YAML template (CVE-2022-23131.yaml) for automated detection of the vulnerability, and a README.md with usage instructions and references. The main attack vector is network-based, targeting the SSO endpoints of Zabbix web interfaces. The exploit is operational, providing a working payload and automation for exploitation.
This repository is a Go-based proof-of-concept exploit for CVE-2022-23131, a SAML authentication bypass vulnerability in Zabbix. The main code is in 'main.go', which implements a CLI tool to test if a target Zabbix instance is vulnerable. The tool works by sending an initial request to the target's '/index.php' endpoint, extracting and decoding the 'zbx_session' cookie, injecting a forged 'saml_data' field with a specified username, and then sending the modified cookie to '/index_sso.php'. If the exploit is successful, the server responds with a redirect to 'zabbix.php?action=dashboard.view', indicating access as the specified user. The repository includes standard Go module files and a README with usage instructions. No hardcoded IPs or domains are present; the target is user-supplied. The exploit demonstrates the vulnerability but does not weaponize it beyond session manipulation.
This repository contains a Python exploit script (zabbix.py) targeting Zabbix servers vulnerable to CVE-2022-23131, an SSO authentication bypass vulnerability. The script forges a valid SSO session by manipulating the 'zbx_session' cookie, allowing an attacker to log in as any user (typically an admin) on the target Zabbix server. The script accepts command-line arguments for the target URL, username, proxy, and a file containing multiple targets. It can test single or multiple Zabbix servers and writes successful login attempts to 'found.txt'. The exploit is operational and automates the attack, requiring only network access to the Zabbix web interface. The only code file is 'zabbix.py', and the repository also includes a README with usage instructions.
This repository contains a Python exploit script (cve-2022-23131.py) and a detailed README for CVE-2022-23131, a vulnerability in Zabbix's SAML authentication flow. The exploit targets Zabbix servers with misconfigured SAML authentication, allowing an attacker to forge a valid session cookie (zbx_session) for any user (default: Admin). The script takes the target Zabbix server URL and optionally a username and custom User-Agent. It retrieves the current zbx_session cookie, decodes and modifies it to include a forged SAML username attribute, re-encodes it, and then attempts to access the Zabbix dashboard as the specified user. If successful, it outputs the forged session cookie, which can be manually set in a browser to gain authenticated access. The repository is straightforward, with the main exploit logic in a single Python file and comprehensive usage instructions in the README. No hardcoded endpoints are present; the target is user-supplied. The exploit is operational, providing a working session cookie for privilege escalation on vulnerable Zabbix instances.
This repository contains a Python exploit script (CVE-2022-23131.py) and a README.md. The exploit targets CVE-2022-23131, an authentication bypass vulnerability in the Zabbix Frontend SSO mechanism. The script works by first retrieving a legitimate 'zbx_session' cookie from the target, decoding and modifying its contents to impersonate a specified user, and then sending a request to the '/index_sso.php' endpoint with the crafted cookie. If the target is vulnerable, the script outputs a valid session cookie that can be used to access the Zabbix dashboard as the chosen user. The README provides usage instructions and describes the affected Zabbix versions. The exploit is operational, requiring a valid username and a vulnerable Zabbix instance with SSO enabled. No fake or destructive code is present; the script is focused on authentication bypass via session cookie manipulation.
This repository contains a proof-of-concept exploit for CVE-2022-23131, a vulnerability in Zabbix's SAML Single Sign-On implementation. The repository consists of a Python script (cve-2022-23131.py) and a README.md file. The script forges a valid 'zbx_signed_session' cookie by extracting and modifying session data from a vulnerable Zabbix instance. The attacker provides the target URL and the username (typically 'Admin'), and the script outputs a forged session cookie. By replacing the session cookie in their browser and using the SAML SSO login, the attacker can gain admin access to the Zabbix management interface. The exploit targets Zabbix servers with SAML SSO enabled and is a network-based attack. No hardcoded endpoints are present; the target is user-supplied. The exploit is a proof-of-concept and does not include weaponized or automated post-exploitation features.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.