Sceawere
Vulnerability Detail
CVE-2026-59563UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Zscaler MCP HMAC Replay Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.6
- Creation Date
- 3h ago
- Vendor
- Zscaler
- Product
- zscaler-mcp-server
- Attack Type
- CWE-305 Authentication bypass by primary weakness
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Zscaler MCP Server versions 0.7.0 and 0.7.1 has an issue where HMAC confirmation tokens were not bound to the target resource identifier, allowing an MCP client or agent to replay a token generated for one resource to affect another resource of the same type. This issue is fixed in version 0.7.2.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.6",
"pubDate": "2026-09-28T13:17:22.160Z",
"pubdate": "2026-09-28T13:17:22.160Z",
"executiveSummary": "Zscaler MCP Server versions 0.7.0 and 0.7.1 are susceptible to an HMAC (Hash-based Message Authentication Code) token replay vulnerability. The security flaw stems from an improper implementation of token validation, wherein HMAC confirmation tokens are not cryptographically bound to specific target resource identifiers. This architectural oversight allows an attacker possessing a valid, intercepted token to replay the authentication material against unauthorized resources of the same type. The vulnerability affects the integrity and authorization controls of the Zscaler MCP server infrastructure. An attacker capable of intercepting legitimate traffic between an MCP client or agent and the server can leverage this flaw to perform unauthorized actions on behalf of the client by redirecting the valid token to an unintended resource. Successful exploitation permits the bypass of resource-specific authorization checks, potentially leading to unauthorized data access or service manipulation. Remediation requires an immediate upgrade to Zscaler MCP Server version 0.7.2, which introduces proper binding of tokens to target identifiers to prevent token reuse across disparate resources.",
"technicalDetails": "The vulnerability resides in the validation logic of the Zscaler MCP Server responsible for verifying incoming HMAC confirmation tokens used by MCP clients and agents. In the affected versions (0.7.0 and 0.7.1), the server-side verification process fails to implement a resource-specific binding mechanism. Consequently, the HMAC tokens are generated based on a scope that lacks the context of the specific target resource identifier.\nRoot Cause: The absence of a unique resource identifier within the HMAC input vector (e.g., as part of the authenticated data payload or 'associated data' in a cryptographic context) allows the server to treat the token as a generic authorization proof rather than a proof tied to a specific resource instance. Because the token validates the authenticity of the client request but not the target resource scope, the server accepts the token as valid for any request targeting the same resource type.\nAttack Flow: 1. Interception: An attacker performs a man-in-the-middle (MITM) attack or otherwise captures a valid HMAC confirmation token sent from an MCP client to a legitimate resource 'A'. 2. Manipulation: The attacker reconstructs a new request targeting unauthorized resource 'B', where 'B' shares the same resource type as 'A'. 3. Replay: The attacker includes the captured token from resource 'A' into the request targeting resource 'B'. 4. Validation Bypass: The Zscaler MCP Server verifies the HMAC signature of the incoming request for resource 'B'. Since the HMAC is mathematically valid for the client's identity and the underlying protocol, the server approves the request, incorrectly assuming the token is scoped to 'B'.\nPost-Exploitation Impact: Exploitation allows an authenticated MCP client to interact with resources they are not authorized to access. By replaying captured tokens, an attacker effectively masks their unauthorized access as a legitimate request originating from the original authorized client. This circumvents server-side access control lists (ACLs) and authorization policies that rely on the presumption that a presented token is inherently bound to a specific target. The issue is fixed in version 0.7.2, where the HMAC generation and validation routines have been updated to include the target resource identifier, ensuring that tokens are strictly scoped to the specific endpoint for which they were intended."
}