9.1
CVE-2026-59564
- EPSS 0.3%
- Veröffentlicht 24.08.2026 13:39:16
- Zuletzt bearbeitet 28.08.2026 18:39:48
- Erkennungen
Authentication bypass between ZCC and client connector portal
An authentication bypass issue exists in communications between affected versions of the Zscaler Client Connector and the Zscaler Client Connector Portal.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerZscaler
≫
Produkt
Client Connector
Default Statusaffected
Version
0
Version <
Windows: 4.6.0.457, 4.7.0.317, 4.8.0.232, 4.9.0.372
Status
affected
Version
0
Version <
MacOS: 4.5.2.312, 4.7.0.292, 4.8.0.191
Status
affected
Version
0
Version <
iOS: 4.5.1
Status
affected
Version
0
Version <
Android: 4.2
Status
affected
Version
0
Version <
ChromeOS: 4.2
Status
affected
Version
0
Version <
Linux: 3.7.2.64, 4.2.1.64
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.3% | 0.22 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| cve@zscaler.com | 9.1 | 3.9 | 5.2 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
|
CWE-304 Missing Critical Step in Authentication
The product implements an authentication technique, but it skips a step that weakens the technique.
https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026