CVE-2026-59563
4.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L
Summary
Zscaler MCP Server versions 0.7.0 and 0.7.1 has an issue where HMAC confirmation tokens were not bound to the target resource identifier, allowing an MCP client or agent to replay a token generated for one resource to affect another resource of the same type. This issue is fixed in version 0.7.2.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Zscaler | zscaler-mcp-server | 0.7.0 < 0.7.2 | affected |
Weaknesses
- CWE-305: CWE-305 Authentication bypass by primary weakness
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: partial
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.