CVE-2026-22569 Details
Description
An incorrect startup configuration of affected versions of Zscaler Client Connector on Windows may cause a limited amount of traffic from being inspected under rare circumstances.
A vulnerability exists in Zscaler Client Connector for Windows, specifically in versions 4.3.0.272, 4.4.0.395, 4.5.0.366, 4.6.0.146, 4.7.0.47, and 4.8.0.63. This vulnerability arises from an incorrect startup configuration that may, under rare circumstances, prevent a limited amount of traffic from being properly inspected. The issue is related to how the application handles DNS responses, particularly when a trusted network is defined by hostname and IP conditions.
Users can update to Zscaler Client Connector version 4.8.0.115 or 4.7.0.141 for Windows, both of which address this vulnerability. Instructions for updating Zscaler Client Connector can be found in the Zscaler Client Connector Release Notes.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 31, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summary-2025 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
| CWE-1289 | Improper Validation of Unsafe Equivalence in Input | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| zscaler client connector | >= 4.7, < 4.7.0.141 >= 4.8, < 4.8.0.63 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 6, 2026 | Initial Analysis | [email protected] |
| Mar 31, 2026 | New CVE Received | [email protected] |