« Back to list

CVE-2026-59569

Status: Awaiting AnalysisHigh (8.1)—

An improper input validation vulnerability in Zscaler Client Connector on Android and ChromeOS allows an attacker to potentially bypass Zscaler controls.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

🎯 ATT&CK techniques

How this vulnerability is exploited and what the attacker gains, in MITRE ATT&CK terms.

AV:L + PR:H sin interacción → escalada de privilegios (T1068). La vulnerabilidad de validación en controles de seguridad Zscaler permite bypass (impersonación/manipulación de políticas T1556) y potencial SSRF/proxy (T1090) al eludir restricciones de red.

Inferred by our analysis agent from the official description, CVSS vector and CWE, and checked by a supervisor. May contain errors.

🛡️ ATT&CK mitigations that cover these techniques

Affected technologies (3)

⚠ AI-inferred from the description — NVD hasn't analyzed this CVE yet, these aren't verified CPEs.

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2026-59569",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-59569",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-09-14T00:00:00+00:00"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "cve@zscaler.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 8.1,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 6,
        "exploitabilityScore": 1.5
      }
    ]
  },
  "affected": [
    {
      "source": "cve@zscaler.com",
      "affectedData": [
        {
          "vendor": "Zscaler",
          "product": "Client Connector",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "Android: 4.2.0.152",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "0",
              "lessThan": "ChromeOS: 4.2.0.152",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "Android",
            "ChromeOS"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-14T15:17:06.603",
  "references": [
    {
      "url": "https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2026",
      "source": "cve@zscaler.com"
    }
  ],
  "vulnStatus": "Awaiting Analysis",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cve@zscaler.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An improper input validation vulnerability in Zscaler Client Connector on Android and ChromeOS allows an attacker to potentially bypass Zscaler controls."
    }
  ],
  "lastModified": "2026-09-18T19:08:02.707",
  "sourceIdentifier": "cve@zscaler.com"
}