CVE-2026-59569: Android ZCC VPN API method privilege escalation
Published Sep 14, 2026
·Updated
An improper input validation vulnerability in Zscaler Client Connector on Android and ChromeOS allows an attacker to potentially bypass Zscaler controls.
Affected Software
1 affected component
Zscaler Zscaler Client Connector
Event History
Sep 14, 2026
CVE Published
via MITRE·02:42 PM
Data Sourced
via MITRE·02:42 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access would an attacker need to exploit this issue?
The CVSS vector indicates local access and high privileges are required. It is not described as a remotely exploitable issue without prior privileged access.
2
What could a successful exploit allow?
A successful exploit could bypass Zscaler controls. The reported impact includes high confidentiality and integrity impact, low availability impact, and an impact beyond the initially affected security authority.
3
How can I determine whether a deployment is affected or whether a fix is available?
The provided information does not identify affected or fixed versions, default-configuration exposure, or detection steps. Review the vendor's 2026 Client Connector app release summary for version and remediation details.