{"api_version":"1","generated_at":"2026-06-14T10:46:25+00:00","cve":"CVE-2026-53407","urls":{"html":"https://cve.report/CVE-2026-53407","api":"https://cve.report/api/cve/CVE-2026-53407.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-53407","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-53407"},"summary":{"title":"CVE-2026-53407","description":"Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allow an unauthenticated user to conduct an escalation of privilege via network access.","state":"PUBLISHED","assigner":"Zoom","published_at":"2026-06-12 19:16:29","updated_at":"2026-06-12 19:16:29"},"problem_types":["CWE-939","CWE-939 CWE-939 Improper authorization in handler for custom URL scheme"],"metrics":[{"version":"3.1","source":"security@zoom.us","type":"Secondary","score":"8.1","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"8.1","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":8.1,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","version":"3.1"}}],"references":[{"url":"https://www.zoom.com/en/trust/security-bulletin/zsb-26010","name":"https://www.zoom.com/en/trust/security-bulletin/zsb-26010","refsource":"security@zoom.us","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-53407","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-53407","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Zoom Communications","product":"Zoom Workplace","version":"affected 7.0.4 custom","platforms":["Android","iOS"]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"53407","cve":"CVE-2026-53407","epss":"0.000380000","percentile":"0.118140000","score_date":"2026-06-13","updated_at":"2026-06-14 00:08:31"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","platforms":["Android","iOS"],"product":"Zoom Workplace","vendor":"Zoom Communications","versions":[{"lessThan":"7.0.4","status":"affected","version":"0","versionType":"custom"}]}],"datePublic":"2026-06-10T12:00:00.000Z","descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allow an unauthenticated user to conduct an escalation of privilege via network access.</p>"}],"value":"Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allow an unauthenticated user to conduct an escalation of privilege via network access."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":8.1,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-939","description":"CWE-939 Improper authorization in handler for custom URL scheme","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-06-12T17:56:26.755Z","orgId":"99b9af0d-a833-4a5d-9e2f-8b1324f35351","shortName":"Zoom"},"references":[{"url":"https://www.zoom.com/en/trust/security-bulletin/zsb-26010"}],"source":{"discovery":"UNKNOWN"},"x_generator":{"engine":"Vulnogram 1.0.0"}}},"cveMetadata":{"assignerOrgId":"99b9af0d-a833-4a5d-9e2f-8b1324f35351","assignerShortName":"Zoom","cveId":"CVE-2026-53407","datePublished":"2026-06-12T17:56:26.755Z","dateReserved":"2026-06-09T10:12:34.854Z","dateUpdated":"2026-06-12T17:56:26.755Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-06-12 19:16:29","lastModifiedDate":"2026-06-12 19:16:29","problem_types":["CWE-939","CWE-939 CWE-939 Improper authorization in handler for custom URL scheme"],"metrics":{"cvssMetricV31":[{"source":"security@zoom.us","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":5.2}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"53407","Ordinal":"1","Title":"CVE-2026-53407","CVE":"CVE-2026-53407","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"53407","Ordinal":"1","NoteData":"Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allow an unauthenticated user to conduct an escalation of privilege via network access.","Type":"Description","Title":"CVE-2026-53407"}]}}}