Description
Path traversal in Zoom VDI Client and Plugins may allow an authenticated user to conduct information disclosure via local access.
Published: 2026-08-11
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a path traversal flaw in the Zoom VDI client and its plugins that allows an authenticated local user to read files outside the intended directory boundaries. This flaw provides the attacker with unauthorized access to sensitive files stored on the host machine, potentially exposing confidential data. The weakness is identified as CWE‑23.

Affected Systems

The flaw affects all versions of the Zoom Communications Zoom VDI product. No specific version constraints are listed in the CNA data, so all published releases may be vulnerable until patched.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity vulnerability, but the EPSS score of less than 1 % suggests a low probability that the flaw will be exploited in the near term. It is not listed in the CISA KEV catalog. The attack requires the user to be authenticated on the system, so it is a local privilege issue rather than a remote exploitation vector. Once accessed locally, the attacker can reclaim data from arbitrary files.

Generated by OpenCVE AI on August 12, 2026 at 21:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Zoom VDI update as per the Zoom Security Bulletin ZSB-26017.
  • Ensure that all Zoom VDI plugins are updated to the latest version supplied in the same bulletin.
  • Restrict local file access for the Zoom VDI processes by setting appropriate file system permissions and enforcing a whitelist of allowed directories.

Generated by OpenCVE AI on August 12, 2026 at 21:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Zoom Communications
Zoom Communications zoom Vdi
Vendors & Products Zoom Communications
Zoom Communications zoom Vdi

Tue, 11 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Description Path traversal in Zoom VDI Client and Plugins may allow an authenticated user to conduct information disclosure via local access.
Title Zoom VDI - Path Traversal
Weaknesses CWE-23
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Zoom Communications Zoom Vdi
cve-icon MITRE

Status: PUBLISHED

Assigner: Zoom

Published:

Updated: 2026-08-11T16:52:33.177Z

Reserved: 2026-06-09T10:18:05.660Z

Link: CVE-2026-53416

cve-icon Vulnrichment

Updated: 2026-08-11T16:51:56.239Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-11T16:17:32.960

Modified: 2026-08-28T18:39:48.167

Link: CVE-2026-53416

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T10:41:06Z

Weaknesses
  • CWE-23

    Relative Path Traversal