{"id":"CVE-2026-59563","title":"Zscaler MCP Server versions 0.7.0 and 0.7.1 has an issue where HMAC confirmation tokens were not bound to the target resource identifier, allowing an MCP client or agent to replay a token generated for one resource to affect another reso…","summary":"Zscaler MCP Server versions 0.7.0 and 0.7.1 has an issue where HMAC confirmation tokens were not bound to the target resource identifier, allowing an MCP client or agent to replay a token generated for one resource to affect another reso…","severity":"medium","cvss":4.6,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L","cwe":["CWE-305"],"vendor":"Zscaler","product":"zscaler-mcp-server","affected":["zscaler-mcp-server >= 0.7.0 < 0.7.2"],"published":"2026-09-28","updated":"2026-09-28","sourceUpdated":"2026-09-28T13:17:22.160","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-59563","references":[{"url":"https://github.com/zscaler/zscaler-mcp-server/pull/41","label":"cve@zscaler.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-28T13:18:33.827712Z"},"ingestedAt":"2026-09-28T13:09:42.230Z","slug":"CVE-2026-59563","body":"## Overview\n\nZscaler MCP Server versions 0.7.0 and 0.7.1 has an issue where HMAC confirmation tokens were not bound to the target resource identifier, allowing an MCP client or agent to replay a token generated for one resource to affect another resource of the same type. This issue is fixed in version 0.7.2.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":25,"depthScoreParts":{"impact":25.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}