ZeroHour

CVE-2026-59567

mass

Local Privilege Escalation in Zscaler Client Connector

CVSS 3.1
8.8 high
EPSS
<1%p1
Published
()
Modified
AI analysis

CVE-2026-59567 describes multiple vulnerabilities in affected versions of Zscaler Client Connector, the endpoint agent for Zscaler's Zero Trust services, that allow local privilege escalation (classified under CWE-280, improper handling of insufficient privileges). An unprivileged local user on a machine running an affected version can trigger the flaw with no user interaction and execute arbitrary code in a privileged context. Successful exploitation gives the attacker elevated-privilege code execution with high impact on confidentiality, integrity and availability (CVSS scope 'changed'), effectively enabling full compromise of the endpoint. Any organization running Zscaler Client Connector on workstations, laptops, or other endpoints with an affected version is exposed. No public proof-of-concept, KEV listing, or in-the-wild exploitation is currently known, and EPSS estimates only about a 0.1% probability of exploitation within 30 days.

What to do: Consult Zscaler's security advisory for CVE-2026-59567 and upgrade Client Connector to the fixed release it specifies (fixed version numbers are not included in the provided data). Verify deployed agent versions via your endpoint/management console and remediate broadly, prioritizing shared or multi-user endpoints and any hosts where untrusted local logon is possible, since exploitation requires local access. Because this is a local privilege escalation rather than a network-facing flaw, it is best treated as a hardening and patch-compliance issue rather than an urgent perimeter incident.

Affected
Zscaler Client Connector
Estimated exposure
massseveral million endpoint installs (>1M users) — Zscaler Client Connector is the standard agent deployed on endpoints of Zscaler Zero Trust Exchange customers, and Zscaler's publicly reported enterprise customer base and protected-user counts imply an installed base in the millions of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Multiple vulnerabilities on affected versions of Zscaler Client Connector allow local privilege escalation, giving an unprivileged user the ability to execute arbitrary code in a privileged context.

Weakness
CWE-280
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.