CVE-2026-59570
massPeer-App Control Flaw in Zscaler Client Connector Enables Tunnel Teardown and Logout
CVE-2026-59570 is an improper input validation flaw (CWE-20) in Zscaler Client Connector that allows a pre-installed peer application on the same endpoint to issue powerful commands against the client: tearing down the Zscaler tunnel, forcing the user's logout, and toggling packet capture. Exploitation is local — an attacker with low-privileged code execution on the machine abuses the client's handling of peer-app requests, with high attack complexity and no user interaction required, and the impact crosses into the protected Zscaler service beyond the vulnerable component. Successful abuse primarily harms integrity and availability, disconnecting users from the Zscaler security service and disrupting sessions, with no direct confidentiality impact per the CVSS vector. Anyone running an affected version of Zscaler Client Connector is exposed, though the flaw requires local access and specific conditions to exploit. There is no evidence of exploitation in the wild, no public PoC, and the CVE is not listed in CISA's KEV catalog.
What to do: Update Zscaler Client Connector to the fixed release identified in Zscaler's security advisory, since the CVE record does not enumerate version numbers. Audit Client Connector logs for unexplained tunnel teardowns, forced logouts, or packet-capture state changes, and restrict which local applications are allowed to communicate with the client. Because exploitation requires local low-privilege code execution, maintain endpoint hardening and least-privilege controls to limit untrusted peer apps.
| Zscaler Client Connector | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
On affected versions of Zscaler client connector, a pre-installed peer app can tear down the Zscaler tunnel, force user logout, and toggle packet capture.
- Weakness
- CWE-20
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.