Home

Description

External Control of File Name or Path in the Mail feature of Zoom Workplace for Windows before 6.6.0 may allow an unauthenticated user to conduct an escalation of privilege via network access.

PUBLISHED Reserved 2026-03-06 | Published 2026-03-11 | Updated 2026-03-12 | Assigner Zoom




CRITICAL: 9.6CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Problem types

CWE-73 External control of file name or path

Product status

Default status
unaffected

see references
affected

References

www.zoom.com/en/trust/security-bulletin/zsb-26005

cve.org (CVE-2026-30903)

nvd.nist.gov (CVE-2026-30903)

Download JSON