9.8
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
CVE-2022-23131 - Zabbix SAML SSO Authentication Bypass + RCE Overview When SAML SSO is enabled, Zabbix stores session data in a client-side cookie zbxsession as a base64-encoded JSON blob. The server never verifies the signature of the samldata field,...
Basic Information
ID
BC1EFC7B-C6E0-528C-BD5D-A2D2ECE15187
Published
Jun 22, 2026 at 07:33
Modified
Jun 22, 2026 at 07:34