OS Command Injection in Zoom Node Meetings Hybrid (ZMH) MMR module and Zoom Node Meeting Connector (MC) MMR module - CVE-2026-22844

 

OS Command Injection in Zoom Node Meetings Hybrid (ZMH) MMR module and Zoom Node Meeting Connector (MC) MMR module - CVE-2026-22844

Published: January 20, 2026


Vulnerability identifier: #VU121695
CSH Severity: Medium
CVSS v4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-22844
CWE-ID: CWE-78
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary shell commands on the target system.

The vulnerability exists due to improper input validation. A remote authenticated user can execute arbitrary OS commands on the Zoom MMR.


Affected software

Zoom Node Meetings Hybrid (ZMH) MMR module
Zoom Node Meeting Connector (MC) MMR module

How to mitigate CVE-2026-22844

Install updates from vendor's website.

Zoom Node Meetings Hybrid (ZMH) MMR module - update to 5.2.1716.0
Zoom Node Meeting Connector (MC) MMR module - update to 5.2.1716.0

External References

Related Security Bulletins