Description
An authentication bypass issue exists in communications between affected versions of the Zscaler Client Connector and the Zscaler Client Connector Portal.
Published: 2026-08-24
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Authentication Bypass between Zscaler Client Connector and its portal
Action: Apply Patch
AI Analysis

Impact

An authentication bypass flaw exists in communications between the Zscaler Client Connector and the Zscaler Client Connector Portal, allowing an unauthorized entity to authenticate as a legitimate user without proper credentials. The vulnerability is identified as CWE‑304, reflecting incorrect authentication handling. A vulnerability of this nature can lead to sub‑account takeover, unmanaged configuration changes, potential lateral movement within a network, and may provide a foothold for further exploitation.

Affected Systems

The impacted product is Zscaler Client Connector. Version details are not supplied in the CVE entry, but the vendor’s 2026 release notes indicate that newer releases contain the fix for this issue.

Risk and Exploitability

The CVSS score of 9.1 indicates a critical level of severity, while the EPSS score is not available, leaving the exact likelihood of exploitation uncertain. The vulnerability is not yet listed in CISA’s KEV catalog, yet the high CVSS coupled with the nature of the flaw suggests that an attacker who can communicate with the client connector port would benefit from a remote authentication bypass, potentially allowing unauthorized access to protected resources.

Generated by OpenCVE AI on August 24, 2026 at 16:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to the latest Zscaler Client Connector release that includes the authentication bypass fix (see the 2026 release notes).
  • Restrict portal access to known administrative IP ranges to reduce the exposure of the authentication endpoint.
  • Enable multi‑factor authentication for the Zscaler Client Connector Portal if supported to add an additional hurdle against bypass attempts.

Generated by OpenCVE AI on August 24, 2026 at 16:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Zscaler
Zscaler client Connector
Vendors & Products Zscaler
Zscaler client Connector

Mon, 24 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 24 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
Description An authentication bypass issue exists in communications between affected versions of the Zscaler Client Connector and the Zscaler Client Connector Portal.
Title Authentication bypass between ZCC and client connector portal
Weaknesses CWE-304
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Zscaler Client Connector
cve-icon MITRE

Status: PUBLISHED

Assigner: Zscaler

Published:

Updated: 2026-08-25T03:56:08.874Z

Reserved: 2026-07-06T06:18:59.633Z

Link: CVE-2026-59564

cve-icon Vulnrichment

Updated: 2026-08-24T13:51:53.702Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-24T14:16:55.690

Modified: 2026-08-28T18:39:48.167

Link: CVE-2026-59564

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T17:00:04Z

Weaknesses
  • CWE-304

    Missing Critical Step in Authentication