Improper privilege management in Zoom Video Communications, Inc. products - CVE-2026-30902
Published: March 10, 2026
Vulnerability identifier: #VU123681
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-30902
CWE-ID: CWE-269
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to improper privilege management. A local user can escalate privileges on the system.
Affected software
Zoom Workplace Desktop App for Windows
Zoom Rooms Client for Windows
Virtual Desktop Infrastructure (VDI)
Zoom Rooms Client for Windows
Virtual Desktop Infrastructure (VDI)
How to mitigate CVE-2026-30902
Install updates from vendor's website.
Zoom Workplace Desktop App for Windows - update to 6.6.0 15547
Zoom Rooms Client for Windows - update to 6.6.0
Virtual Desktop Infrastructure (VDI) - addressed in versions 6.4.15.26810, 6.5.13.26820, 6.6.10.26830
Zoom Rooms Client for Windows - update to 6.6.0
Virtual Desktop Infrastructure (VDI) - addressed in versions 6.4.15.26810, 6.5.13.26820, 6.6.10.26830