CVE-2023-22892: Smartbear Zephyr Enterprise

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

There exists an information disclosure vulnerability in SmartBear Zephyr Enterprise through 7.15.0 that could be exploited by unauthenticated users to read arbitrary files from Zephyr instances.

Affected products

  • Smartbear Zephyr Enterprise: up to and including 7.15

Published 2023-03-08. Last modified 2026-06-17.