What happened
Zscaler MCP Server's HMAC confirmation-token mechanism did not bind tokens to the target resource identifier, allowing replay across same-type resources. Fixed in 0.7.2; advisory published to GitHub Security Advisory database on 2026-09-28.
Why it matters
MCP confirmation tokens are the human-approval control protecting destructive Zscaler resources; unbound tokens let an agent or malicious MCP client satisfy the confirmation step against the wrong resource, weakening the last guardrail between an agent and security-device changes.
Attack vector
HMAC confirmation tokens were generated without binding to the target resource identifier, so a token obtained for one resource is accepted to confirm an operation on another resource of the same type.
Affected systems
zscaler/zscaler-mcp-server 0.7.0 and 0.7.1
Mitigation
Upgrade Zscaler MCP Server to 0.7.2 (fix per pull #41 / GHSA-6wjq-5f4c-p8f7).