CVE-2026-22567

Plain English Summary

AI-powered analysis for quick understanding

This vulnerability allows an authenticated administrator to potentially execute backend functions by entering specific inputs in the Zscaler Internet Access Admin Portal. However, it only occurs under limited scenarios where the input validation is not properly enforced.

Technical Description

Improper validation of user-supplied input in the ZIA Admin UI could allow an authenticated administrator to initiate backend functions through specific input fields in limited scenarios.

CVSS Vector Analysis

Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredHigh
User InteractionNone
Confidentiality ImpactNone
Integrity ImpactLow
Availability ImpactNone
ScopeUnchanged

Vector String

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N

Exploit Resources

Search for proof-of-concept code and exploit modules

Official References

Est. Bounty
$374($100-$500)
Vendor Response
Grade APatched in 2 days

Quick Information

Published

Feb 23, 2026

about 1 month ago

Last Modified

Feb 26, 2026

about 1 month ago

Vendor

zscaler

Product

zscaler internet access admin portal