CVE-2026-30368

A client-side authorization flaw in Lightspeed Classroom v5.1.2.1763770643 allows unauthenticated attackers to impersonate users by bypassing integrity checks and abusing client-generated authorization tokens, leading to unauthorized control and monitoring of student devices.
Configurations

No configuration.

History

27 Apr 2026, 11:16

Type Values Removed Values Added
References
  • () https://github.com/truekas/ls-poc -
References () https://tasty-hovercraft-9b9.notion.site/Enabling-Unauthorized-Remote-Control-of-Student-Devices-with-Lightspeed-Classroom-2ec5157f5b4a800c9eefc5526479820a - () https://tasty-hovercraft-9b9.notion.site/Enabling-Unauthorized-Remote-Control-of-Student-Devices-with-Lightspeed-Classroom-2ec5157f5b4a800c9eefc5526479820a -

27 Apr 2026, 08:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4
CWE CWE-863

24 Apr 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-24 16:16

Updated : 2026-04-27 11:16


NVD link : CVE-2026-30368

Mitre link : CVE-2026-30368

CVE.ORG link : CVE-2026-30368


JSON object : View

Products Affected

No product.

CWE
CWE-863

Incorrect Authorization