Zoom VDI - Path Traversal

  • ZSB-26018
  • CVE-2026-53416
  • High
  • 7.1
  • CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Path traversal in Zoom VDI Client and Plugins may allow an authenticated user to conduct information disclosure via local access.

 

Users can help keep themselves secure by applying the latest updates available at https://zoom.us/download.

  • Zoom Workplace VDI Client for Windows before versions 7.0.11 and 6.6.15 in their respective branches.
  • Zoom Workplace VDI Plugins all supported platforms before 7.0.11 and 6.6.15 in their respective branches.

Reported by CK Tan from the XOR team at JPMorgan Chase

Revision Date Description
1.0 08/11/2026

Initial publication.