Junglewise Threat Intelligence

CVE-2026-59570: Zscaler Client Connector peer app access control bypass

CVE-2026-59570 · Severity: high · CVSS 7.5 · Published 2026-09-14

Technologies: Zscaler Client Connector. Vendors: Zscaler.

Executive brief

Zscaler Client Connector is security software that creates a secure tunnel between end-user devices and Zscaler's security cloud. A pre-installed peer application can exploit a vulnerability to disconnect users from the Zscaler tunnel, force them to log out, and enable packet capture—actions that should be restricted. An attacker with access to a peer app on the same device could disrupt security monitoring and data protection.

Technical details

This vulnerability in Zscaler Client Connector allows a pre-installed peer application to perform privileged operations (tunnel teardown, user logout, packet capture toggling) without proper authorization checks. The root cause is insufficient access control validation when peer applications interact with the Zscaler client process. Attack vector is local (same-device peer app execution); no network access or elevated privileges are explicitly required beyond the peer app's pre-installed presence. An attacker controlling or compromising a peer application can disrupt the secure tunnel and bypass security controls. Patches are available via Zscaler's official release notes.

Affected products

  • Zscaler Client Connector

Timeline

  • 2026-09-14: disclosed

References

Related threats