Impact
This vulnerability involves multiple flaws in Zscaler Client Connector that allow a remote, unauthenticated, unprivileged user to execute arbitrary code within the ZCC process. The weakness is an instance of improper input validation (CWE‑20). Successful exploitation could compromise the confidentiality, integrity, and availability of the host running the client, potentially granting full control of the operating system.
Affected Systems
The affected product is Zscaler Client Connector. Specific affected versions are not disclosed in the CVE data; it applies to all pre‑release‑summary‑2026 releases that have not yet been updated by the vendor.
Risk and Exploitability
The high CVSS score of 9.1 indicates a severe risk. EPSS information is not available, and the vulnerability is not currently listed in CISA KEV. Based on the description, the likely attack vector is remote network access to the Client Connector service, and no authentication or privilege escalation is required. An attacker can reach the vulnerable component from any system that can communicate with the client, triggering code execution with the privileges of the ZCC process.
OpenCVE Enrichment