← Vulnerability feed

Vulnerability record · CVE-2019-17382 · published 9 October 2019

CVE-2019-17382: Zabbix dashboard login bypass via insecure direct object reference

Zabbix · Zabbix

Zabbix through 4.4 exposes the dashboard view endpoint (zabbix.php?action=dashboard.view&dashboardid=1) in a way that lets an unauthenticated attacker bypass the login page and reach the dashboard. From there the attacker can create Dashboard, Report, Screen, or Map objects anonymously, and those objects are visible to other users and administrators. The flaw is an insecure direct object reference (CWE-639) with a critical CVSS 3.1 score of 9.1.

9.1 CVSS 3.1 Critical EPSS 54% · top 1.0% CWE-639 · Insecure direct object reference
9.1CVSS 3.1 base score, v2 6.4
54%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

An issue was discovered in zabbix.php?action=dashboard.view&dashboardid=1 in Zabbix through 4.4. An attacker can bypass the login page and access the dashboard page, and then create a Dashboard, Report, Screen, or Map without any Username/Password (i.e., anonymously). All created elements (Dashboard/Report/Screen/Map) are accessible by other users and by an admin.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

critical priorityCVSS 9.1 with no authentication or user interaction required, a public exploit, and very high EPSS probability make this an urgent exposure for any internet-reachable Zabbix instance.

What it is

Zabbix through 4.4 exposes the dashboard view endpoint (zabbix.php?action=dashboard.view&dashboardid=1) in a way that lets an unauthenticated attacker bypass the login page and reach the dashboard. From there the attacker can create Dashboard, Report, Screen, or Map objects anonymously, and those objects are visible to other users and administrators. The flaw is an insecure direct object reference (CWE-639) with a critical CVSS 3.1 score of 9.1.

Impact

An attacker gains unauthenticated access to the Zabbix dashboard and can create persistent Dashboard, Report, Screen, and Map objects that are visible to legitimate users and admins. This undermines access control and can be used to inject content or clutter the monitoring interface, though the record does not state whether data modification or code execution is possible.

Attack surface

Reachable over the network via the web interface at zabbix.php?action=dashboard.view&dashboardid=1; the CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates no authentication and no user interaction are required.

Exploitation

A public Exploit-DB entry (47467) exists, and EPSS shows a 30-day probability of 0.5415 (98.9th percentile), indicating high likelihood of exploitation; the CVE is not listed in CISA KEV.

What to do

  • Upgrade Zabbix to a version later than 4.4 that contains the fix, or apply the vendor patch for the affected branch.
  • Restrict network access to the Zabbix web frontend to trusted management networks or VPN.
  • Enforce authentication at a reverse proxy or WAF in front of Zabbix so unauthenticated requests to zabbix.php cannot reach the application.
  • Audit and remove any unexpected Dashboard, Report, Screen, or Map objects created anonymously.
  • Monitor vendor and Debian LTS advisories for backported fixes if running an older distribution package.

Detection

  • Search web access logs for requests to zabbix.php?action=dashboard.view&dashboardid=1 that lack a valid authenticated session.
  • Alert on creation of Dashboard, Report, Screen, or Map objects by unauthenticated or unknown users.
  • Review Zabbix audit logs for anonymous or unexpected object creation events.
  • Correlate source IPs hitting the dashboard endpoint with known exploit signatures or scanning activity.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-17382 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-23131Zabbix Frontend SAML SSO authentication bypass via session spoofingZabbix Frontend fails to verify the user login stored in the session when SAML SSO authentication is enabled, allowing session data to be modified. A…KEVEPSS 96%analysed5.3CVE-2022-23134Zabbix Frontend setup.php improper access control allows unauthenticated config changeAfter initial setup, some steps of Zabbix Frontend's setup.php remain reachable by unauthenticated users rather than only super-administrators. An at…KEVEPSS 95%analysed10.0CVE-2007-0640Zabbix vulnerabilityBuffer overflow in ZABBIX before 1.1.5 has unknown impact and attack vectors related to "SNMP IP addresses."EPSS 2.0%9.9CVE-2024-42327Zabbix frontend SQL injection in CUser addRelatedObjectsThe CUser.addRelatedObjects function in the Zabbix frontend contains an SQL injection reachable through the CUser.get API call. Any account with API …EPSS 79%analysed9.8CVE-2022-43516Microsoft windows firewall vulnerabilityA Firewall Rule which allows all incoming TCP connections to all programs from any source and to all ports is created in Windows Firewall after Zabbi…EPSS 0.95%9.8CVE-2020-11800Zabbix vulnerabilityZabbix Server 2.2.x and 3.0.x before 3.0.31, and 3.2 allows remote attackers to execute arbitrary code.EPSS 9.2%9.8CVE-2013-3738Zabbix improper input validation vulnerabilityA File Inclusion vulnerability exists in Zabbix 2.0.6 due to inadequate sanitization of request strings in CGI scripts, which could let a remote mali…EPSS 3.1%9.8CVE-2013-5743Zabbix SQL injection in multiple componentsZabbix versions 1.8.x before 1.8.18rc1, 2.0.x before 2.0.9rc1, and 2.1.x before 2.1.7 contain multiple SQL injection vulnerabilities. The record does…EPSS 80%analysed

Source: NIST National Vulnerability Database (record CVE-2019-17382), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.