CVE-2026-59569 PUBLISHED

Android ZCC VPN API method privilege escalation

Assigner: Zscaler
Reserved: 06.07.2026 Published: 14.09.2026 Updated: 14.09.2026

An improper input validation vulnerability in Zscaler Client Connector on Android and ChromeOS allows an attacker to potentially bypass Zscaler controls.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L
CVSS Score: 8.1

Product Status

Vendor Zscaler
Product Client Connector
Versions Default: affected
  • affected from 0 to Android: 4.2.0.152 (excl.)
  • affected from 0 to ChromeOS: 4.2.0.152 (excl.)

References

Problem Types

  • CWE-20 Improper input validation CWE

Impacts

  • CAPEC-233 Privilege Escalation