CVE-2026-22568Disclosure(zscaler / zscaler_internet_access_admin_portal)

LOWCVSS 2.7 · LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper neutralization of special elements in user-supplied input within the ZIA Admin UI could allow an authenticated administrator to access or retrieve unauthorized internal information in rare conditions.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • zscaler_internet_access_admin_portal

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-02-23); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
zscaler_internet_access_admin_portal

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-23: 2Mentions · 2026-02-24: 1Technical Details · 2026-02-23: 2Technical Details · 2026-02-24: 102-2302-24
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-232
Disclosure2
2026-02-241
Disclosure1
Full discourse3 posts
  • ThreatCluster@threatcluster
    Disclosure

    Researchers disclose RCE flaws CVE-2026-22568 and CVE-2026-22567 in ZIA Admin UI, allowing admins to execute code via improper user input handling. #Vulnerability https://threatcluster.io/cluster/remote-code-execution-vulnerabilities-in-zia-admin-ui-identi-c3364fc3

    Post summary

    Researchers have disclosed two RCE vulnerabilities (CVE-2026-22568 and CVE-2026-22567) in ZIA Admin UI that allow code execution via improper input handling.

    0001063
    79 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-22568 Improper neutralization of special elements in user-supplied input within the ZIA Admin UI could allow an authenticated administrator to access or retrieve unauthoriz… https://www.cve.org/CVERecord?id=CVE-2026-22568

    Post summary

    CVE-2026-22568 is a vulnerability in the ZIA Admin UI that allows authenticated administrators to access unauthorized data due to improper neutralization of special elements in user‑supplied input.

    00000132
    56.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-22568 Authenticated Information Disclosure Vulnerability in Zscaler Internet Access Admin UI https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-22568

    Post summary

    The text announces CVE-2026-22568, an authenticated information disclosure vulnerability in Zscaler Internet Access Admin UI, and links to a vulnerability details page.

    0000065
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appzscalerzscaler_internet_access_admin_portal---

Explore more