CVE-2026-59564: Authentication bypass between ZCC and client connector portal
Published Aug 24, 2026
·Updated
An authentication bypass issue exists in communications between affected versions of the Zscaler Client Connector and the Zscaler Client Connector Portal.
Affected Software
1 affected component
Zscaler Client Connector=
Event History
Aug 24, 2026
CVE Published
via MITRE·01:39 PM
Data Sourced
via MITRE·01:39 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The vulnerability is rated with no privileges required and no user interaction required. Its network attack vector indicates the affected communication path can be targeted remotely.
2
What is the potential impact if exploitation succeeds?
The supplied severity vector indicates high confidentiality and integrity impact, with no availability impact. Successful exploitation could therefore expose sensitive information or enable unauthorized modification, but is not assessed as causing a service outage.