Vulnerability record · CVE-2022-23134 · published 13 January 2022
CVE-2022-23134: Zabbix Frontend setup.php improper access control allows unauthenticated config change
Zabbix · Zabbix
After initial setup, some steps of Zabbix Frontend's setup.php remain reachable by unauthenticated users rather than only super-administrators. An attacker can pass step checks and potentially alter the frontend configuration. The flaw is an access control and authentication failure in the setup workflow.
Description
After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by unauthenticated users as well. Malicious actor can pass step checks and potentially change the configuration of Zabbix Frontend.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Automated analysis
high priorityThe flaw is remotely reachable without authentication and is in CISA KEV with very high EPSS, though CVSS impact is limited to low integrity.
What it is
After initial setup, some steps of Zabbix Frontend's setup.php remain reachable by unauthenticated users rather than only super-administrators. An attacker can pass step checks and potentially alter the frontend configuration. The flaw is an access control and authentication failure in the setup workflow.
Impact
An unauthenticated attacker can modify Zabbix Frontend configuration, which can undermine the integrity of the monitoring platform and its data. The CVSS vector rates only low integrity impact with no confidentiality or availability impact.
Attack surface
Reachable over the network via the setup.php endpoint with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. The description does not specify which setup steps remain exposed or the exact request sequence.
Exploitation
CVE-2022-23134 is listed in CISA KEV with a due date of 2022-03-08, indicating known exploitation, and EPSS shows a 30-day probability of 0.84657 (99.7th percentile). No ransomware campaign use is documented.
What to do
- Apply the vendor patch referenced in Zabbix advisory ZBX-20384 and update Zabbix Frontend to a fixed release.
- Apply the Debian and Fedora package updates listed in the distribution advisories.
- Restrict network access to the Zabbix Frontend setup interface and block setup.php once initial configuration is complete.
- Verify setup is finished and remove or lock down any remaining setup entry points.
- Monitor for unexpected changes to Zabbix Frontend configuration after deployment.
Detection
- Review web server logs for requests to setup.php from unauthenticated or unexpected source IPs.
- Alert on configuration changes to Zabbix Frontend made outside approved maintenance windows.
- Compare current frontend configuration against a known-good baseline to spot unauthorized edits.
- Correlate setup.php access with authentication logs to identify requests lacking a valid super-admin session.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2022-23134 to the Known Exploited Vulnerabilities catalog on 22 February 2022 as "Zabbix Frontend Improper Access Control Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 8 March 2022.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2022-23134 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-23134), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.