Impact
An authentication bypass flaw exists in communications between the Zscaler Client Connector and the Zscaler Client Connector Portal, allowing an unauthorized entity to authenticate as a legitimate user without proper credentials. The vulnerability is identified as CWE‑304, reflecting incorrect authentication handling. A vulnerability of this nature can lead to sub‑account takeover, unmanaged configuration changes, potential lateral movement within a network, and may provide a foothold for further exploitation.
Affected Systems
The impacted product is Zscaler Client Connector. Version details are not supplied in the CVE entry, but the vendor’s 2026 release notes indicate that newer releases contain the fix for this issue.
Risk and Exploitability
The CVSS score of 9.1 indicates a critical level of severity, while the EPSS score is not available, leaving the exact likelihood of exploitation uncertain. The vulnerability is not yet listed in CISA’s KEV catalog, yet the high CVSS coupled with the nature of the flaw suggests that an attacker who can communicate with the client connector port would benefit from a remote authentication bypass, potentially allowing unauthorized access to protected resources.
OpenCVE Enrichment