CVE-2026-30906: High severity Zoom Zoom Rooms for Windows vulnerability
Published May 13, 2026
·Updated
Untrusted search path in the installer for Zoom Rooms for Windows before version 7.0.0 may allow an authenticated user to enable an escalation of privilege via local access.
Affected Software
2 affected components
Zoom Zoom Rooms for Windows<7.0.0
Zoom Rooms Windows<7.0.0
Event History
May 13, 2026
CVE Published
via MITRE·06:03 PM
Data Sourced
via MITRE·06:03 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-30906?
CVE-2026-30906 has a moderate severity rating as it allows for escalation of privilege through local access.
2
How do I fix CVE-2026-30906?
To mitigate CVE-2026-30906, update Zoom Rooms for Windows to version 7.0.0 or later.
3
Who is affected by CVE-2026-30906?
Users of Zoom Rooms for Windows versions prior to 7.0.0 are affected by CVE-2026-30906.
4
What type of vulnerability is CVE-2026-30906?
CVE-2026-30906 is classified as an untrusted search path vulnerability.
5
Can CVE-2026-30906 be exploited remotely?
CVE-2026-30906 requires local access, so it cannot be exploited remotely.