CVE-2026-22568

Plain English Summary

AI-powered analysis for quick understanding

This vulnerability allows an authenticated administrator to potentially access unauthorized internal information through the Zscaler Internet Access Admin portal. However, this can only happen under rare conditions where the input provided by the user is not properly handled.

Technical Description

Improper neutralization of special elements in user-supplied input within the ZIA Admin UI could allow an authenticated administrator to access or retrieve unauthorized internal information in rare conditions.

CVSS Vector Analysis

Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredHigh
User InteractionNone
Confidentiality ImpactLow
Integrity ImpactNone
Availability ImpactNone
ScopeUnchanged

Vector String

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N

Exploit Resources

Search for proof-of-concept code and exploit modules

Official References