# CVE-2026-53407

## Summary

- **CVE ID:** CVE-2026-53407
- **Severity:** HIGH
- **CVSS Score:** 8.1 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N)
- **CWE:** CWE-939
- **Published:** Jun 12, 2026
- **Last Modified:** Jun 16, 2026

## Description

Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allow an unauthenticated user to conduct an escalation of privilege via network access.

## Affected Products

- Zoom Communications — Zoom Workplace (0)

## References

- [CNA](https://www.zoom.com/en/trust/security-bulletin/zsb-26010)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.23%
- **EPSS Percentile:** 13.8

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-12._