Description
A file type attribution issue in Zscaler Internet Access File Type Control evaluation rules may allow improper evaluation of File Type Control policies in rare circumstances.
Published: 2026-09-18
Score: 4.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Policy Bypass
Action: Monitor
AI Analysis

Impact

A file type attribution issue exists in Zscaler Internet Access File Type Control evaluation rules that may allow improper evaluation of File Type Control policies in rare circumstances. The flaw is an input validation weakness that could enable an attacker to trick the system into misclassifying file types, potentially bypassing restrictions and permitting the transmission of files that are normally blocked. Because the vulnerability is rooted in improper input validation (CWE‑20), the primary impact is a policy bypass that may facilitate the delivery of malicious or unintended content.

Affected Systems

This issue affects the Zscaler Internet Access product, specifically the File Type Control component. No specific version information is provided, so all current releases that implement the described evaluation rules are potentially impacted unless a patch has been applied after the documented release.

Risk and Exploitability

The CVSS score of 4.4 indicates a low severity threat. The EPSS score is < 1% and the vulnerability is not listed in CISA’s KEV catalog, suggesting that widespread exploitation is not known. Based on the description, it is inferred that the vulnerability requires specific conditions to trigger a bypass, and no public exploitation has been reported. Overall, the risk is low, but the potential to undermine policy enforcement warrants monitoring for abnormal file type handling events.

Generated by OpenCVE AI on September 19, 2026 at 19:13 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Validate Zscaler File Type Control rules and update to the latest policy version as soon as a fix is released
  • Apply additional secondary controls such as sandboxing or endpoint protection to detect malicious files that may bypass the file type filter
  • Regularly review Zscaler logs for unexpected file type evaluations or rule failures

Generated by OpenCVE AI on September 19, 2026 at 19:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Zscaler
Zscaler zia File Type Control
Vendors & Products Zscaler
Zscaler zia File Type Control

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Description A file type attribution issue in Zscaler Internet Access File Type Control evaluation rules may allow improper evaluation of File Type Control policies in rare circumstances.
Title File Type Control rule bypass
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Zscaler Zia File Type Control
cve-icon MITRE

Status: PUBLISHED

Assigner: Zscaler

Published:

Updated: 2026-09-18T17:47:19.524Z

Reserved: 2026-02-05T05:00:40.581Z

Link: CVE-2026-25684

cve-icon Vulnrichment

Updated: 2026-09-18T17:47:05.615Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T15:17:07.837

Modified: 2026-09-18T19:08:02.707

Link: CVE-2026-25684

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:29:33Z

Weaknesses
  • CWE-20

    Improper Input Validation