ZscalerCVE-2026-59563
Zscaler MCP Server versions 0.7.0 and 0.7.1 has an issue where HMAC...
Medium4.6CVE-2026-59563 · Published Sep 28, 2026
Zscaler MCP Server versions 0.7.0 and 0.7.1 has an issue where HMAC confirmation tokens were not bound to the target resource identifier, allowing an MCP client or agent to replay a token generated for one resource to affect another resource of the same type. This issue is fixed in version 0.7.2.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| zscaler-mcp-server Product | >= 0.7.0, < 0.7.2 | 0.7.2 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-305
More Zscaler advisories
All Zscaler| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 18 | Zscaler: improper input validation | Medium4.4 | No fix yet |
| Sep 14 | Zscaler Client Connector: improper input validation | High8.1 | Android: 4.2.0.152+1 more |
| Sep 14 | Zscaler Client Connector: improper input validation | High7.5 | Android: 4.2.0.152+1 more |
| Sep 14 | Zscaler Client Connector: race condition | High8.1 | 4.6.0.486+3 more |
| Aug 24 | Zscaler Client Connector: privilege escalation | High8.8 | Windows: 4.6.0.457+8 more |
| Aug 24 | Zscaler Client Connector: remote code execution | Critical9.1 | Windows: 4.6.0.457+8 more |