HMAC Token Replay Vulnerability in Zscaler MCP Server
CVE-2026-59563

4.6MEDIUM

Key Information:

Vendor

Zscaler

Vendor
CVE Published:
28 September 2026

What is CVE-2026-59563?

The Zscaler MCP Server versions 0.7.0 and 0.7.1 have a vulnerability that arises from the improper handling of HMAC confirmation tokens. These tokens were not correctly bound to their target resource identifiers, permitting malicious actors to replay a token intended for one resource against another resource of the same type. This issue can compromise the integrity of resource access. Users are urged to update to version 0.7.2, where this vulnerability has been addressed.

Affected Version(s)

zscaler-mcp-server 0.7.0 < 0.7.2

References

CVSS V3.1

Score:
4.6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Sebastián Alba Vives
.