2026-08-24 13:44CVE-2026-59568Zscaler
PUBLISHED5.2CWE-20

Remote Code Execution

Multiple vulnerabilities on affected versions of Zscaler Client Connector allow remote code execution, giving an unauthenticated, unprivileged user the ability to execute arbitrary code in the ZCC context.

Problem type

Affected products

Zscaler

Client Connector

< Windows: 4.6.0.457, 4.7.0.317, 4.8.0.232, 4.9.0.372 - AFFECTED

< MacOS: 4.5.2.312, 4.7.0.292, 4.8.0.191 - AFFECTED

< Linux: 3.7.2.64, 4.2.1.64 - AFFECTED

< Android: 4.2 - AFFECTED

< ChromeOS: 4.2 - AFFECTED

< iOS: 4.5.1 - AFFECTED

References

GitHub Security Advisories

GHSA-m6h7-qfgx-p2gj

Multiple vulnerabilities on affected versions of Zscaler Client Connector allow remote code...

https://github.com/advisories/GHSA-m6h7-qfgx-p2gj

Multiple vulnerabilities on affected versions of Zscaler Client Connector allow remote code execution, giving an unauthenticated, unprivileged user the ability to execute arbitrary code in the ZCC context.

JSON source

https://cveawg.mitre.org/api/cve/CVE-2026-59568
Click to expand
{
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "cveMetadata": {
    "cveId": "CVE-2026-59568",
    "assignerOrgId": "73c6f63b-efac-410d-a0a9-569700f85a04",
    "assignerShortName": "Zscaler",
    "dateUpdated": "2026-08-24T13:44:21.795Z",
    "dateReserved": "2026-07-06T06:18:59.633Z",
    "datePublished": "2026-08-24T13:44:21.795Z",
    "state": "PUBLISHED"
  },
  "containers": {
    "cna": {
      "providerMetadata": {
        "orgId": "73c6f63b-efac-410d-a0a9-569700f85a04",
        "shortName": "Zscaler",
        "dateUpdated": "2026-08-24T13:44:21.795Z"
      },
      "datePublic": "2026-08-21T09:48:00.000Z",
      "title": "Remote Code Execution",
      "descriptions": [
        {
          "lang": "en",
          "value": "Multiple vulnerabilities on affected versions of Zscaler Client Connector allow remote code execution, giving an unauthenticated, unprivileged user the ability to execute arbitrary code in the ZCC context.",
          "supportingMedia": [
            {
              "type": "text/html",
              "base64": false,
              "value": "Multiple vulnerabilities on affected versions of Zscaler Client Connector allow remote code execution, giving an unauthenticated, unprivileged user the ability to execute arbitrary code in the ZCC context."
            }
          ]
        }
      ],
      "affected": [
        {
          "vendor": "Zscaler",
          "product": "Client Connector",
          "platforms": [
            "Windows",
            "MacOS",
            "Linux",
            "iOS",
            "Android",
            "ChromeOS"
          ],
          "defaultStatus": "unaffected",
          "versions": [
            {
              "version": "0",
              "status": "affected",
              "versionType": "custom",
              "lessThan": "Windows: 4.6.0.457, 4.7.0.317, 4.8.0.232, 4.9.0.372"
            },
            {
              "version": "0",
              "status": "affected",
              "versionType": "custom",
              "lessThan": "MacOS: 4.5.2.312, 4.7.0.292, 4.8.0.191"
            },
            {
              "version": "0",
              "status": "affected",
              "versionType": "custom",
              "lessThan": "Linux: 3.7.2.64, 4.2.1.64"
            },
            {
              "version": "0",
              "status": "affected",
              "versionType": "custom",
              "lessThan": "Android: 4.2"
            },
            {
              "version": "0",
              "status": "affected",
              "versionType": "custom",
              "lessThan": "ChromeOS: 4.2"
            },
            {
              "version": "0",
              "status": "affected",
              "versionType": "custom",
              "lessThan": "iOS: 4.5.1"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "lang": "en",
              "description": "CWE-20 Improper input validation",
              "cweId": "CWE-20",
              "type": "CWE"
            }
          ]
        }
      ],
      "references": [
        {
          "url": "https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026"
        }
      ],
      "impacts": [
        {
          "capecId": "CAPEC-253",
          "descriptions": [
            {
              "lang": "en",
              "value": "CAPEC-253 Remote Code Inclusion"
            }
          ]
        }
      ],
      "metrics": [
        {
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ],
          "cvssV3_1": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "scope": "UNCHANGED",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "availabilityImpact": "NONE",
            "baseScore": 9.1,
            "baseSeverity": "CRITICAL"
          }
        }
      ]
    }
  }
}