Skip to content
ZscalerCVE-2026-59563

Zscaler MCP Server versions 0.7.0 and 0.7.1 has an issue where HMAC...

Medium4.6CVE-2026-59563 · Published Sep 28, 2026

Zscaler MCP Server versions 0.7.0 and 0.7.1 has an issue where HMAC confirmation tokens were not bound to the target resource identifier, allowing an MCP client or agent to replay a token generated for one resource to affect another resource of the same type. This issue is fixed in version 0.7.2.

Zscaler advisory

Affected versions

PackageAffectedFixed in
zscaler-mcp-server
Product
>= 0.7.0, < 0.7.20.7.2
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-305

More Zscaler advisories

All Zscaler
Advisory
Zscaler: improper input validation
Medium4.4Sep 18
Zscaler Client Connector: improper input validation
High8.1Sep 14
Zscaler Client Connector: improper input validation
High7.5Sep 14
Zscaler Client Connector: race condition
High8.1Sep 14
Zscaler Client Connector: privilege escalation
High8.8Aug 24
Zscaler Client Connector: remote code execution
Critical9.1Aug 24

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.