CVE-2026-59570

Summary

On affected versions of Zscaler client connector, a pre-installed peer app can tear down the Zscaler tunnel, force user logout, and toggle packet capture.

Affected Software

VendorProductVersion RangeStatus
ZscalerClient Connector0 < Android: 4.2.0.152affected
ZscalerClient Connector0 < ChromeOS: 4.2.0.152affected

Weaknesses

  • CWE-20: CWE-20 Improper input validation

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References