Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allow an unauthenticated user to conduct an escalation of privilege via network access.
References
| Link | Resource |
|---|---|
| https://www.zoom.com/en/trust/security-bulletin/zsb-26010 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
16 Jun 2026, 18:59
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.zoom.com/en/trust/security-bulletin/zsb-26010 - Vendor Advisory | |
| First Time |
Zoom
Zoom meeting Software Development Kit Zoom workplace |
|
| CPE | cpe:2.3:a:zoom:workplace:*:*:*:*:*:iphone_os:*:* cpe:2.3:a:zoom:meeting_software_development_kit:*:*:*:*:*:android:*:* cpe:2.3:a:zoom:meeting_software_development_kit:*:*:*:*:*:iphone_os:*:* cpe:2.3:a:zoom:workplace:*:*:*:*:*:android:*:* |
12 Jun 2026, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-12 19:16
Updated : 2026-06-16 18:59
NVD link : CVE-2026-53408
Mitre link : CVE-2026-53408
CVE.ORG link : CVE-2026-53408
JSON object : View
Products Affected
zoom
- meeting_software_development_kit
- workplace
CWE
CWE-939
Improper Authorization in Handler for Custom URL Scheme
