CVE-2026-25684 PUBLISHED

File Type Control rule bypass

Assigner: Zscaler
Reserved: 05.02.2026 Published: 18.09.2026 Updated: 18.09.2026

A file type attribution issue in Zscaler Internet Access File Type Control evaluation rules may allow improper evaluation of File Type Control policies in rare circumstances.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N
CVSS Score: 4.4

Product Status

Vendor Zscaler
Product ZIA File Type Control
Versions Default: unaffected
  • unaffected from 0 to 6.2r (current) (excl.)

Credits

  • Nate Subra and Nathan Fowler finder

References

Problem Types

  • CWE-20 Improper input validation CWE

Impacts

  • CAPEC-554 Functionality Bypass