Vulnerability record · CVE-2019-17382 · published 9 October 2019
CVE-2019-17382: Zabbix dashboard login bypass via insecure direct object reference
Zabbix · Zabbix
Zabbix through 4.4 exposes the dashboard view endpoint (zabbix.php?action=dashboard.view&dashboardid=1) in a way that lets an unauthenticated attacker bypass the login page and reach the dashboard. From there the attacker can create Dashboard, Report, Screen, or Map objects anonymously, and those objects are visible to other users and administrators. The flaw is an insecure direct object reference (CWE-639) with a critical CVSS 3.1 score of 9.1.
Description
An issue was discovered in zabbix.php?action=dashboard.view&dashboardid=1 in Zabbix through 4.4. An attacker can bypass the login page and access the dashboard page, and then create a Dashboard, Report, Screen, or Map without any Username/Password (i.e., anonymously). All created elements (Dashboard/Report/Screen/Map) are accessible by other users and by an admin.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Automated analysis
critical priorityCVSS 9.1 with no authentication or user interaction required, a public exploit, and very high EPSS probability make this an urgent exposure for any internet-reachable Zabbix instance.
What it is
Zabbix through 4.4 exposes the dashboard view endpoint (zabbix.php?action=dashboard.view&dashboardid=1) in a way that lets an unauthenticated attacker bypass the login page and reach the dashboard. From there the attacker can create Dashboard, Report, Screen, or Map objects anonymously, and those objects are visible to other users and administrators. The flaw is an insecure direct object reference (CWE-639) with a critical CVSS 3.1 score of 9.1.
Impact
An attacker gains unauthenticated access to the Zabbix dashboard and can create persistent Dashboard, Report, Screen, and Map objects that are visible to legitimate users and admins. This undermines access control and can be used to inject content or clutter the monitoring interface, though the record does not state whether data modification or code execution is possible.
Attack surface
Reachable over the network via the web interface at zabbix.php?action=dashboard.view&dashboardid=1; the CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates no authentication and no user interaction are required.
Exploitation
A public Exploit-DB entry (47467) exists, and EPSS shows a 30-day probability of 0.5415 (98.9th percentile), indicating high likelihood of exploitation; the CVE is not listed in CISA KEV.
What to do
- Upgrade Zabbix to a version later than 4.4 that contains the fix, or apply the vendor patch for the affected branch.
- Restrict network access to the Zabbix web frontend to trusted management networks or VPN.
- Enforce authentication at a reverse proxy or WAF in front of Zabbix so unauthenticated requests to zabbix.php cannot reach the application.
- Audit and remove any unexpected Dashboard, Report, Screen, or Map objects created anonymously.
- Monitor vendor and Debian LTS advisories for backported fixes if running an older distribution package.
Detection
- Search web access logs for requests to zabbix.php?action=dashboard.view&dashboardid=1 that lack a valid authenticated session.
- Alert on creation of Dashboard, Report, Screen, or Map objects by unauthenticated or unknown users.
- Review Zabbix audit logs for anonymous or unexpected object creation events.
- Correlate source IPs hitting the dashboard endpoint with known exploit signatures or scanning activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://lists.debian.org/debian-lts-announce/2023/08/msg00027.html | |
| https://www.exploit-db.com/exploits/47467 | ExploitThird Party AdvisoryVDB Entry |
| https://lists.debian.org/debian-lts-announce/2023/08/msg00027.html | |
| https://www.exploit-db.com/exploits/47467 | ExploitThird Party AdvisoryVDB Entry |
Track CVE-2019-17382 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-17382), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.