CVE-2026-22567Disclosure(zscaler / zscaler_internet_access_admin_portal)

LOWCVSS 2.7 · LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper validation of user-supplied input in the ZIA Admin UI could allow an authenticated administrator to initiate backend functions through specific input fields in limited scenarios.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • zscaler_internet_access_admin_portal

Threat summary

  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 5 signals
  • Disclosure: 5 classified signals
  • Peaked 3d ago at 2 mentions (2026-02-23); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
zscaler_internet_access_admin_portal

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-02-23: 2Mentions · 2026-02-24: 1Mentions · 2026-02-27: 1Mentions · 2026-02-28: 1Technical Details · 2026-02-23: 2Technical Details · 2026-02-24: 1Technical Details · 2026-02-27: 1Technical Details · 2026-02-28: 102-2302-2402-2702-28
Signal classification1 categories
Disclosure
5100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-232
Disclosure2
2026-02-241
Disclosure1
2026-02-271
Disclosure1
2026-02-281
Disclosure1
Full discourse5 posts
  • ThreatCluster@threatcluster
    Disclosure

    Researchers disclose RCE flaws CVE-2026-22568 and CVE-2026-22567 in ZIA Admin UI, allowing admins to execute code via improper user input handling. #Vulnerability https://threatcluster.io/cluster/remote-code-execution-vulnerabilities-in-zia-admin-ui-identi-c3364fc3

    Post summary

    Researchers have disclosed two RCE vulnerabilities (CVE-2026-22568 and CVE-2026-22567) in ZIA Admin UI that allow code execution via improper input handling.

    0001063
    79 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-22567 (CVSS:7.6, HIGH) is Analyzed. Improper validation of user-supplied input in the ZIA Admin UI could allow an authenticated administrator to initiate ba..https://nvd.nist.gov/vuln/detail/CVE-2026-22567 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE-2026-22567, noting its CVSS score and a description of the vulnerability, but provides no PoC, exploit code, or patch information.

    0000030
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-22567 (CVSS:7.6, HIGH) is Analyzed. Improper validation of user-supplied input in the ZIA Admin UI could allow an authenticated administrator to initiate ba..https://nvd.nist.gov/vuln/detail/CVE-2026-22567 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The tweet announces CVE‑2026‑22567, highlighting an improper input validation flaw in ZIA Admin UI with a CVSS of 7.6, without mentioning active exploitation, PoC, or patches.

    0000029
    173 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-22567 Improper validation of user-supplied input in the ZIA Admin UI could allow an authenticated administrator to initiate backend functions through specific input fields … https://www.cve.org/CVERecord?id=CVE-2026-22567

    Post summary

    The CVE details an improper input validation flaw in the ZIA Admin UI that could allow authenticated administrators to trigger backend functions through specific input fields.

    00000137
    56.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-22567 Authenticated Input Validation Bypass in Zscaler Internet Access Admin UI https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-22567

    Post summary

    The entry lists CVE‑2026‑22567 and describes it as an authenticated input‑validation bypass in Zscaler’s Admin UI, but does not provide a PoC, exploit code, patch details, or evidence of active exploitation.

    0000056
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appzscalerzscaler_internet_access_admin_portal---

Explore more