HMAC Token Replay Vulnerability in Zscaler MCP Server
CVE-2026-59563
4.6MEDIUM
What is CVE-2026-59563?
The Zscaler MCP Server versions 0.7.0 and 0.7.1 have a vulnerability that arises from the improper handling of HMAC confirmation tokens. These tokens were not correctly bound to their target resource identifiers, permitting malicious actors to replay a token intended for one resource against another resource of the same type. This issue can compromise the integrity of resource access. Users are urged to update to version 0.7.2, where this vulnerability has been addressed.
Affected Version(s)
zscaler-mcp-server 0.7.0 < 0.7.2
