PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-16449 zsadmin2025 CVE debrief

A sql injection vulnerability was found in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. The vulnerability exists in the function OrderItem.asc/OrderItem.desc of the file /api/system/sys/dept/page of the component com.zs.sys.dept.controller.SysDeptController. This manipulation of the argument orderField causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified.

Vendor
zsadmin2025
Product
ZS-Admin
CVSS
LOW 2.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-21
Original CVE updated
2026-07-22
Advisory published
2026-07-21
Advisory updated
2026-07-22

Who should care

Users of zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead should be aware of this vulnerability and take necessary actions to protect their systems, including reviewing system deployments, assessing potential impact, and applying patches or mitigations promptly.

Technical summary

The vulnerability is caused by the manipulation of the argument orderField in the function OrderItem.asc/OrderItem.desc of the file /api/system/sys/dept/page of the component com.zs.sys.dept.controller.SysDeptController. This manipulation leads to sql injection, allowing remote attackers to potentially compromise the system. The attack surface and potential impact on confidentiality, integrity, and availability should be evaluated based on the system's role and existing security controls.

Defensive priority

Low-Moderate due to public exploit disclosure and potential for remote exploitation in zsadmin2025 ZS-Admin deployments. Users should assess their exposure and apply patches or mitigations promptly if affected systems are found in managed environments. Compensating controls like monitoring and web application firewalls may be considered while updates are planned and verified through normal change control processes. Exceptions should be tracked, and retesting of remediated assets should be done before closing the item, with evidence documented for closure review. The attack surface and potential impact on confidentiality, integrity, and availability should be evaluated based on the system's role and existing security controls. Additional verification tasks may be necessary to confirm affected scope and validate vendor guidance within specific operational contexts. Limited source detail suggests caution and defensive verification tasks are warranted until more comprehensive information is available or confirmed through official channels. This situation may change as more information becomes available or confirmed through official channels, and users should stay informed about updates and new advisories related to this vulnerability. The vulnerability's potential impact on business operations and data security should also be assessed, and appropriate measures should be taken to mitigate risks effectively. Users are advised to review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance, and plan vendor-supported updates or mitigations through normal change control where exposure is confirmed. Compensating controls for exposed systems should be reviewed while remediation is scheduled and verified, and relevant monitoring, detection, and logs for exposed assets should be checked for extra review. Tracking exceptions, retesting remediated assets, and closing the item only after evidence is documented are crucial steps in managing this vulnerability effectively. The situation may evolve with further details from the vendor or additional research, and users should be prepared to adjust their defensive strategies as needed

Recommended defensive actions

  • Apply the latest patch or update to zsadmin2025 ZS-Admin
  • Restrict access to the /api/system/sys/dept/page endpoint
  • Monitor for suspicious activity on the system
  • Use a web application firewall to detect and prevent sql injection attacks
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The vulnerability was determined in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. The impacted element is the function OrderItem.asc/OrderItem.desc of the file /api/system/sys/dept/page of the component com.zs.sys.dept.controller.SysDeptController. This vulnerability allows for sql injection through manipulation of the argument orderField. The attack can be carried out remotely. Evidence is based on limited source detail and may change as more information becomes available. Users should verify the vulnerability details and affected scope with the vendor and consider applying patches or mitigations.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T16:17:07.313Z and has not been modified since then.