Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allow an unauthenticated user to conduct an escalation of privilege via network access.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.zoom.com/en/trust/security-bulletin/zsb-26010 |
|
History
Fri, 12 Jun 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated Privilege Escalation via Improper Authorization in Zoom Workplace URL Scheme | |
| First Time appeared |
Zoom Communications
Zoom Communications zoom Workplace |
|
| Vendors & Products |
Zoom Communications
Zoom Communications zoom Workplace |
Fri, 12 Jun 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 12 Jun 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allow an unauthenticated user to conduct an escalation of privilege via network access. | |
| Weaknesses | CWE-939 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Zoom
Published:
Updated: 2026-06-12T19:05:19.573Z
Reserved: 2026-06-09T10:12:34.854Z
Link: CVE-2026-53407
Updated: 2026-06-12T19:05:15.789Z
Status : Received
Published: 2026-06-12T19:16:29.973
Modified: 2026-06-12T19:16:29.973
Link: CVE-2026-53407
No data.
OpenCVE Enrichment
Updated: 2026-06-12T19:30:31Z