Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
2.7

ZIA Admin UI allows access to unauthorized data

CVE-2026-22568
Summary

An authenticated administrator can access internal data by exploiting a weakness in the ZIA Admin UI. This can happen in rare situations. To mitigate this risk, ensure that user input is properly validated and sanitized within the admin interface.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versionsFix available
zscaler zscaler_internet_access_admin_portal <= 6.2r –
Original title
Improper neutralization of special elements in user-supplied input within the ZIA Admin UI could allow an authenticated administrator to access or retrieve unauthorized internal information in rare...
Original description
Improper neutralization of special elements in user-supplied input within the ZIA Admin UI could allow an authenticated administrator to access or retrieve unauthorized internal information in rare conditions.
nvd CVSS3.1 2.7
Vulnerability type
CWE-20 Improper Input Validation
Published: 23 Feb 2026 · Updated: 12 Mar 2026 · First seen: 6 Mar 2026