CVE-2026-22569 PUBLISHED

Incorrect startup configuration in ZCC

Assigner: Zscaler
Reserved: 07.01.2026 Published: 31.03.2026 Updated: 31.03.2026

An incorrect startup configuration of affected versions of Zscaler Client Connector on Windows may cause a limited amount of traffic from being inspected under rare circumstances.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
CVSS Score: 5.4

Product Status

Vendor Zscaler
Product Zscaler Client Connector
Versions Default: unaffected
  • affected from 4.7 to 4.7.0.141 (excl.)
  • affected from 4.8 to 4.8.0.63 (excl.)

Credits

  • Jordan Eberst, CISA reporter

References

Problem Types

  • CWE-1289 Improper validation of unsafe equivalence in input CWE

Impacts

  • CAPEC-554 Functionality Bypass