CVE-2026-59563

Summary

Zscaler MCP Server versions 0.7.0 and 0.7.1 has an issue where HMAC confirmation tokens were not bound to the target resource identifier, allowing an MCP client or agent to replay a token generated for one resource to affect another resource of the same type. This issue is fixed in version 0.7.2.

Affected Software

VendorProductVersion RangeStatus
Zscalerzscaler-mcp-server0.7.0 < 0.7.2affected

Weaknesses

  • CWE-305: CWE-305 Authentication bypass by primary weakness

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References