Description
An improper input validation vulnerability in Zscaler Client Connector on Android and ChromeOS allows an attacker to potentially bypass Zscaler controls.
Published: 2026-09-14
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation or Bypass of Network Controls
Action: Assess Impact
AI Analysis

Impact

Zscaler Client Connector on Android and ChromeOS contains an improper input validation flaw (CWE-20) that may allow an attacker to send crafted requests and bypass Zscaler controls. The flaw can enable unauthorized network access or elevate an attacker’s privileges relative to the VPN service, potentially undermining the security posture of the client’s network traffic.

Affected Systems

Zscaler Client Connector installations on Android and ChromeOS are affected. No specific version information is supplied, so all installed instances of the client on these operating systems should be considered vulnerable.

Risk and Exploitability

The CVSS score of 8.1 indicates high severity, while the EPSS score of less than 1% and absence from the CISA KEV catalog imply that the vulnerability has not yet been actively exploited in the wild. It is inferred that the attack vector relies on an attacker crafting malicious input to the client; this may be achieved via local or network interfaces that the client exposes, but the exact method of delivery is not explicitly detailed in the description.

Generated by OpenCVE AI on September 21, 2026 at 00:12 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Zscaler Client Connector to the latest version once the vendor releases a patch that fixes the input validation issue.
  • If no patch is immediately available, consult Zscaler documentation for interim mitigations and apply any recommended controls.
  • Restrict VPN API usage to trusted applications and monitor logs for unexpected or malformed VPN API calls.

Generated by OpenCVE AI on September 21, 2026 at 00:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
First Time appeared Zscaler
Zscaler client Connector
Vendors & Products Zscaler
Zscaler client Connector

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description An improper input validation vulnerability in Zscaler Client Connector on Android and ChromeOS allows an attacker to potentially bypass Zscaler controls.
Title Android ZCC VPN API method privilege escalation
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Zscaler Client Connector
cve-icon MITRE

Status: PUBLISHED

Assigner: Zscaler

Published:

Updated: 2026-09-15T03:56:05.059Z

Reserved: 2026-07-06T06:18:59.633Z

Link: CVE-2026-59569

cve-icon Vulnrichment

Updated: 2026-09-14T15:39:36.763Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T15:17:06.603

Modified: 2026-09-18T19:08:02.707

Link: CVE-2026-59569

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T00:15:06Z

Weaknesses
  • CWE-20

    Improper Input Validation