Multiple vulnerabilities on affected versions of Zscaler Client Connector allow remote code execution, giving an unauthenticated, unprivileged user the ability to execute arbitrary code in the ZCC context.
PUBLISHED5.2CWE-20
Remote Code Execution
Problem type
Affected products
Zscaler
Client Connector
< Windows: 4.6.0.457, 4.7.0.317, 4.8.0.232, 4.9.0.372 - AFFECTED
< MacOS: 4.5.2.312, 4.7.0.292, 4.8.0.191 - AFFECTED
< Linux: 3.7.2.64, 4.2.1.64 - AFFECTED
< Android: 4.2 - AFFECTED
< ChromeOS: 4.2 - AFFECTED
< iOS: 4.5.1 - AFFECTED
References
GitHub Security Advisories
GHSA-m6h7-qfgx-p2gj
Multiple vulnerabilities on affected versions of Zscaler Client Connector allow remote code...
https://github.com/advisories/GHSA-m6h7-qfgx-p2gjMultiple vulnerabilities on affected versions of Zscaler Client Connector allow remote code execution, giving an unauthenticated, unprivileged user the ability to execute arbitrary code in the ZCC context.
JSON source
https://cveawg.mitre.org/api/cve/CVE-2026-59568Click to expand
{
"dataType": "CVE_RECORD",
"dataVersion": "5.2",
"cveMetadata": {
"cveId": "CVE-2026-59568",
"assignerOrgId": "73c6f63b-efac-410d-a0a9-569700f85a04",
"assignerShortName": "Zscaler",
"dateUpdated": "2026-08-24T13:44:21.795Z",
"dateReserved": "2026-07-06T06:18:59.633Z",
"datePublished": "2026-08-24T13:44:21.795Z",
"state": "PUBLISHED"
},
"containers": {
"cna": {
"providerMetadata": {
"orgId": "73c6f63b-efac-410d-a0a9-569700f85a04",
"shortName": "Zscaler",
"dateUpdated": "2026-08-24T13:44:21.795Z"
},
"datePublic": "2026-08-21T09:48:00.000Z",
"title": "Remote Code Execution",
"descriptions": [
{
"lang": "en",
"value": "Multiple vulnerabilities on affected versions of Zscaler Client Connector allow remote code execution, giving an unauthenticated, unprivileged user the ability to execute arbitrary code in the ZCC context.",
"supportingMedia": [
{
"type": "text/html",
"base64": false,
"value": "Multiple vulnerabilities on affected versions of Zscaler Client Connector allow remote code execution, giving an unauthenticated, unprivileged user the ability to execute arbitrary code in the ZCC context."
}
]
}
],
"affected": [
{
"vendor": "Zscaler",
"product": "Client Connector",
"platforms": [
"Windows",
"MacOS",
"Linux",
"iOS",
"Android",
"ChromeOS"
],
"defaultStatus": "unaffected",
"versions": [
{
"version": "0",
"status": "affected",
"versionType": "custom",
"lessThan": "Windows: 4.6.0.457, 4.7.0.317, 4.8.0.232, 4.9.0.372"
},
{
"version": "0",
"status": "affected",
"versionType": "custom",
"lessThan": "MacOS: 4.5.2.312, 4.7.0.292, 4.8.0.191"
},
{
"version": "0",
"status": "affected",
"versionType": "custom",
"lessThan": "Linux: 3.7.2.64, 4.2.1.64"
},
{
"version": "0",
"status": "affected",
"versionType": "custom",
"lessThan": "Android: 4.2"
},
{
"version": "0",
"status": "affected",
"versionType": "custom",
"lessThan": "ChromeOS: 4.2"
},
{
"version": "0",
"status": "affected",
"versionType": "custom",
"lessThan": "iOS: 4.5.1"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"lang": "en",
"description": "CWE-20 Improper input validation",
"cweId": "CWE-20",
"type": "CWE"
}
]
}
],
"references": [
{
"url": "https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026"
}
],
"impacts": [
{
"capecId": "CAPEC-253",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-253 Remote Code Inclusion"
}
]
}
],
"metrics": [
{
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
],
"cvssV3_1": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "NONE",
"baseScore": 9.1,
"baseSeverity": "CRITICAL"
}
}
]
}
}
}