Improper Authorization Vulnerability in Zoom Workplace for Android and iOS
CVE-2026-53407

8.1HIGH

Key Information:

Vendor
CVE Published:
12 June 2026

What is CVE-2026-53407?

An improper authorization vulnerability exists in the handler for custom URL schemes in Zoom Workplace prior to versions 7.0.4 for Android and 7.0.3 for iOS. This flaw may allow unauthenticated users to escalate privileges through network access, potentially compromising user data and application security. It is crucial for organizations using these versions to implement security measures and update their applications to the latest versions to mitigate risks.

Affected Version(s)

Zoom Workplace Android 0 < 7.0.4

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.