CVE-2023-22891: Smartbear Zephyr Enterprise

High severity, CVSS 8.1. EPSS: 0.5% chance of exploitation in the next 30 days.

There exists a privilege escalation vulnerability in SmartBear Zephyr Enterprise through 7.15.0 that could be exploited by authorized users to reset passwords for other accounts.

Affected products

  • Smartbear Zephyr Enterprise: up to and including 7.15

Published 2023-03-08. Last modified 2026-06-17.