Home

Description

Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allow an unauthenticated user to conduct an escalation of privilege via network access.

PUBLISHED Reserved 2026-06-09 | Published 2026-06-12 | Updated 2026-06-16 | Assigner Zoom




HIGH: 8.1CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Problem types

CWE-939 Improper authorization in handler for custom URL scheme

Product status

Default status
unaffected

Any version before 7.0.4
affected

References

www.zoom.com/en/trust/security-bulletin/zsb-26010

cve.org (CVE-2026-53407)

nvd.nist.gov (CVE-2026-53407)

Download JSON