CVE-2026-59567

Summary

Multiple vulnerabilities on affected versions of Zscaler Client Connector allow local privilege escalation, giving an unprivileged user the ability to execute arbitrary code in a privileged context.

Affected Software

VendorProductVersion RangeStatus
ZscalerClient Connector0 < Windows: 4.6.0.457, 4.7.0.317, 4.8.0.232, 4.9.0372affected
ZscalerClient Connector0 < MacOS: 4.5.2.312, 4.7.0.292, 4.8.0.191affected
ZscalerClient Connector0 < Linux: 3.7.2.64, 4.2.1.64affected

Weaknesses

  • CWE-280: CWE-280 Improper handling of insufficient permissions or privileges

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References