Junglewise Threat Intelligence

CVE-2026-59567: Zscaler Client Connector local privilege escalation

CVE-2026-59567 · Severity: high · CVSS 8.8 · Published 2026-08-24

Technologies: Zscaler Client Connector. Vendors: Zscaler.

Executive brief

Zscaler Client Connector is a security software that protects endpoints by enforcing security policies and controlling network traffic. Unprivileged users on affected systems can escalate their privileges and execute arbitrary code with system-level access, potentially compromising the entire device and bypassing security controls.

Technical details

Multiple vulnerabilities in Zscaler Client Connector allow local privilege escalation (LPE) attacks. The vulnerabilities enable unprivileged local users to execute arbitrary code in a privileged context, typically through a flaw in how the application handles permissions or processes. Attack preconditions require local access to the affected system. An attacker with a standard user account can gain administrative or system privileges, leading to full device compromise. Fixes are expected in patched versions; users should check Zscaler's release notes for the specific affected versions and available patches.

Affected products

  • Zscaler Client Connector

Timeline

  • 2026-08-24: disclosed

References

Related threats