A client-side authorization flaw in Lightspeed Classroom v5.1.2.1763770643 allows unauthenticated attackers to impersonate users by bypassing integrity checks and abusing client-generated authorization tokens, leading to unauthorized control and monitoring of student devices.
References
Configurations
No configuration.
History
27 Apr 2026, 11:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
|
| References | () https://tasty-hovercraft-9b9.notion.site/Enabling-Unauthorized-Remote-Control-of-Student-Devices-with-Lightspeed-Classroom-2ec5157f5b4a800c9eefc5526479820a - |
27 Apr 2026, 08:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.4 |
| CWE | CWE-863 |
24 Apr 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-24 16:16
Updated : 2026-04-27 11:16
NVD link : CVE-2026-30368
Mitre link : CVE-2026-30368
CVE.ORG link : CVE-2026-30368
JSON object : View
Products Affected
No product.
CWE
CWE-863
Incorrect Authorization
