{"id":"CVE-2026-59563","published":"2026-09-28T13:17:22.160","lastModified":"2026-09-28T15:17:17.493","description":"Zscaler MCP Server versions 0.7.0 and 0.7.1 has an issue where HMAC confirmation tokens were not bound to the target resource identifier, allowing an MCP client or agent to replay a token generated for one resource to affect another resource of the same type. This issue is fixed in version 0.7.2.","cvssScore":4.6,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L","cwes":["CWE-305"],"vendors":[],"products":[],"references":[{"url":"https://github.com/zscaler/zscaler-mcp-server/pull/41","tags":[]}],"exploitRefs":[{"url":"https://github.com/zscaler/zscaler-mcp-server/pull/41","tags":[]}],"hasPoc":true,"ai":null}