Description
Multiple vulnerabilities on affected versions of Zscaler Client Connector allow local privilege escalation, giving an unprivileged user the ability to execute arbitrary code in a privileged context.
Published: 2026-08-24
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Patch Now
AI Analysis

Impact

The reported flaws in Zscaler Client Connector allow a local, unprivileged user to obtain elevated privileges, enabling the execution of arbitrary code with administrative rights. This results in a potential compromise of confidentiality, integrity, and availability, giving attackers full control over the affected system. The vulnerabilities are mapped to CWE-280, indicating an improper permission assignment issue.

Affected Systems

The sole vendor/product impacted is Zscaler Client Connector. All installed instances that have not yet been updated to the latest release are susceptible, as the vulnerability list does not specify precise version ranges. Administrators should assume that every current release may be affected until an official patch is released.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity flaw. The EPSS score is unavailable and the vulnerability is not included in CISA’s KEV catalog, which suggests there is no confirmed exploitation in the wild yet. The attack vector is local. An attacker must have local access to the host, such as physical presence or a user account with read access to the Client Connector process, to exploit the flaw. Once the privilege escalation succeeds, the attacker can execute any code on the machine, including installing malware or extracting sensitive data.

Generated by OpenCVE AI on August 24, 2026 at 20:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Zscaler Client Connector to the latest released version that contains the fix.
  • If upgrade is not possible, disable the Client Connector service to prevent local exploitation until a patch becomes available.
  • Review and enforce least privilege for local user accounts that run the Client Connector, ensuring they do not have unnecessary elevated rights.

Generated by OpenCVE AI on August 24, 2026 at 20:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Zscaler
Zscaler client Connector
Vendors & Products Zscaler
Zscaler client Connector

Mon, 24 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 24 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Description Multiple vulnerabilities on affected versions of Zscaler Client Connector allow local privilege escalation, giving an unprivileged user the ability to execute arbitrary code in a privileged context.
Title Local privilege escalation
Weaknesses CWE-280
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Zscaler Client Connector
cve-icon MITRE

Status: PUBLISHED

Assigner: Zscaler

Published:

Updated: 2026-08-25T03:56:58.533Z

Reserved: 2026-07-06T06:18:59.633Z

Link: CVE-2026-59567

cve-icon Vulnrichment

Updated: 2026-08-24T15:17:11.568Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-24T14:16:56.080

Modified: 2026-08-28T18:39:48.167

Link: CVE-2026-59567

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T20:15:04Z

Weaknesses
  • CWE-280

    Improper Handling of Insufficient Permissions or Privileges