Executive brief
Zscaler Client Connector is a software agent that manages secure network access for remote employees. An authentication bypass vulnerability in communications between the client and its portal could allow an attacker to impersonate legitimate users or gain unauthorized access to protected resources, potentially compromising employee data and network security.
Technical details
An authentication bypass vulnerability exists in the communications protocol between affected versions of Zscaler Client Connector and the Zscaler Client Connector Portal. The vulnerability allows attackers to circumvent authentication mechanisms without valid credentials. The exact attack vector and preconditions are not detailed in the available advisory text, but the critical severity rating suggests an easily exploitable flaw with significant impact. Patches are available through Zscaler client connector releases.
Affected products
- Zscaler Client Connector <UNKNOWN>
Timeline
- 2026-08-24: disclosed