Zscaler Internet & SaaS Access
cpe:2.3:a:zscaler:zscaler_internet_access_admin_portal:*:*:*:*:*:*:*
A vulnerability exists in the Zscaler Internet Access (ZIA) Admin UI due to improper validation of user-supplied input. This issue could allow an authenticated administrator to trigger backend functions through specific input fields, but only in limited scenarios.
Exploitation of this vulnerability could lead to unauthorized initiation of backend functions by an authenticated administrator.
Users can upgrade to the Zscaler Internet Access version released on December 17, 2025, which addresses this vulnerability by ensuring proper validation of user input in the Admin Portal.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.