Vulnerability  ·  2026-09-29

Zscaler MCP Server: HMAC confirmation tokens not bound to target resource (token replay)

VulnerabilityLow impactGlobalCVE-2026-59563
Zscaler MCP Server's HMAC confirmation-token mechanism did not bind tokens to the target resource identifier, allowing replay across same-type resources. Fixed in 0.7.2; advisory published to GitHub Security Advisory database on 2026-09-28.
MCP confirmation tokens are the human-approval control protecting destructive Zscaler resources; unbound tokens let an agent or malicious MCP client satisfy the confirmation step against the wrong resource, weakening the last guardrail between an agent and security-device changes.
HMAC confirmation tokens were generated without binding to the target resource identifier, so a token obtained for one resource is accepted to confirm an operation on another resource of the same type.
zscaler/zscaler-mcp-server 0.7.0 and 0.7.1
Upgrade Zscaler MCP Server to 0.7.2 (fix per pull #41 / GHSA-6wjq-5f4c-p8f7).
GitHub advisory GHSA-6wjq-5f4c-p8f7NVD CVE-2026-59563
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →