CVE-2026-22567

Improper validation of user-supplied input in the ZIA Admin UI could allow an authenticated administrator to initiate backend functions through specific input fields in limited scenarios.
Configurations

Configuration 1 (hide)

cpe:2.3:a:zscaler:zscaler_internet_access_admin_portal:*:*:*:*:*:*:*:*

History

26 Feb 2026, 16:44

Type Values Removed Values Added
References () https://help.zscaler.com/zia/release-upgrade-summary-2025?applicable_category=zscalertwo.net&deployment_date=2025-12-17&id=1538575 - () https://help.zscaler.com/zia/release-upgrade-summary-2025?applicable_category=zscalertwo.net&deployment_date=2025-12-17&id=1538575 - Release Notes, Vendor Advisory
First Time Zscaler
Zscaler zscaler Internet Access Admin Portal
CWE NVD-CWE-noinfo
Summary
  • (es) Validación indebida de la entrada proporcionada por el usuario en la UI de administración de ZIA podría permitir a un administrador autenticado iniciar funciones de backend a través de campos de entrada específicos en escenarios limitados.
CPE cpe:2.3:a:zscaler:zscaler_internet_access_admin_portal:*:*:*:*:*:*:*:*

23 Feb 2026, 17:23

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-23 17:23

Updated : 2026-02-26 16:44


NVD link : CVE-2026-22567

Mitre link : CVE-2026-22567

CVE.ORG link : CVE-2026-22567


JSON object : View

Products Affected

zscaler

  • zscaler_internet_access_admin_portal
CWE
CWE-20

Improper Input Validation

NVD-CWE-noinfo