Zoom Improper Input Validation Vulnerability Allowing Account Takeover

Vulnerability

A vulnerability exists in the Zoom Desktop Client for Windows and the Zoom VDI Client for Windows, prior to version 7.0.0 and 7.0.10, respectively, as well as versions 6.6.15 and 6.5.18 in their respective branches. This vulnerability arises from improper input validation, which may enable an unauthenticated user to perform an account takeover via network access.

Impact

Exploitation of this vulnerability could lead to unauthorized account takeover.

Remediation

Users are advised to update to the latest version of the Zoom Desktop Client for Windows or the Zoom VDI Client for Windows. The latest version can be downloaded from the Zoom Download Center.

Added: Jul 16, 2026, 10:45 PM
Updated: Jul 16, 2026, 10:45 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
4.7
remediation
7.7
relevance
9.6
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.