CVE-2026-59563
Received Received - Intake

HMAC Token Replay in Zscaler MCP Server

Vulnerability report for CVE-2026-59563, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: Zscaler, Inc.

Description

Zscaler MCP Server versions 0.7.0 and 0.7.1 has an issue where HMAC confirmation tokens were not bound to the target resource identifier, allowing an MCP client or agent to replay a token generated for one resource to affect another resource of the same type. This issue is fixed in version 0.7.2.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
zscaler mcp_server 0.7.2

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-305 The authentication algorithm is sound, but the implemented mechanism can be bypassed as the result of a separate weakness that is primary to the authentication error.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Zscaler MCP Server versions 0.7.0 and 0.7.1 had a flaw where HMAC confirmation tokens were not linked to specific resources. This allowed attackers to reuse tokens generated for one resource on another resource of the same type, enabling unauthorized actions.

Detection Guidance

To detect this vulnerability, check if your Zscaler MCP Server version is 0.7.0 or 0.7.1. Verify if HMAC confirmation tokens are not bound to specific resource identifiers by inspecting token generation and validation logic in the server logs or code.

Impact Analysis

An attacker could exploit this to perform unauthorized operations on your resources by replaying tokens. This could lead to data manipulation, deletion, or other unintended actions if they gain access to a valid token.

Compliance Impact

This vulnerability could lead to unauthorized access or data breaches, violating GDPR's integrity and confidentiality requirements or HIPAA's safeguards for protected health information. Compliance may be compromised if unauthorized actions occur.

Mitigation Strategies

Upgrade to Zscaler MCP Server version 0.7.2 or later to ensure HMAC tokens are bound to specific resources. Review and update any custom scripts or integrations that rely on token validation to enforce resource-specific binding.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-59563. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart