Skip to content
ZscalerCVE-2026-59569

Zscaler Client Connector: improper input validation

High8.1CVE-2026-59569 · Published Sep 14, 2026 · updated Sep 18, 2026

An improper input validation vulnerability in Zscaler Client Connector on Android and ChromeOS allows an attacker to potentially bypass Zscaler controls.

Zscaler advisory

Affected versions

PackageAffectedFixed in
Client Connector
Product
< Android: 4.2.0.152Android: 4.2.0.152
< ChromeOS: 4.2.0.152ChromeOS: 4.2.0.152
Details and references
CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-20

More Zscaler advisories

All Zscaler
Advisory
Zscaler: improper input validation
Medium4.4Sep 18
Zscaler Client Connector: improper input validation
High7.5Sep 14
Zscaler Client Connector: race condition
High8.1Sep 14
Zscaler Client Connector: privilege escalation
High8.8Aug 24
Zscaler Client Connector: remote code execution
Critical9.1Aug 24
Zscaler Client Connector: authentication bypass
Critical9.1Aug 24

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.