CVE-2026-53407: Critical severity Zoom Zoom Workplace (Android) vulnerability
Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allow an unauthenticated user to conduct an escalation of privilege via network access.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Zoom Workplaceto a version that resolves this vulnerability.Fixed in 7.0.4 - Upgrade
Upgrade
Zoom Workplaceto a version that resolves this vulnerability.Fixed in 7.0.3
Event History
Frequently Asked Questions
What is the severity of CVE-2026-53407?
The severity of CVE-2026-53407 is rated as high, with a score of 8.1.
How do I fix CVE-2026-53407?
To fix CVE-2026-53407, upgrade to Zoom Workplace version 7.0.4 for Android and 7.0.3 for iOS.
What impact does CVE-2026-53407 have on users?
CVE-2026-53407 allows an unauthenticated user to escalate privileges via network access, potentially compromising user data.
Which versions of Zoom are affected by CVE-2026-53407?
CVE-2026-53407 affects Zoom Workplace before version 7.0.4 for Android and before version 7.0.3 for iOS.
What type of vulnerability is CVE-2026-53407?
CVE-2026-53407 is categorized as an Improper Authorization vulnerability within Zoom's custom URL scheme.