CVE-2026-30905 – Zoom Workplace VDI Plugin and Zoom Rooms
“A collaboration tool can become a control point if privilege boundaries fail.”
This patch addresses two High severity vulnerabilities affecting Zoom Workplace VDI Plugin and Zoom Rooms. These issues could allow attackers to escalate privileges or execute unauthorized actions within affected environments. CVE-2026-30905 has a CVSS score of 7.8, which is High severity. CVE-2026-30906 has a CVSS score of 7.8, which is High severity. The update strengthens permission controls and improves how these components enforce security boundaries.
No verified exploitation has been confirmed. However, given these tools are widely deployed in enterprise collaboration and virtual desktop environments, successful exploitation could impact user sessions, system integrity, and sensitive communications.
Key Details
- Affected Product
- Zoom Workplace Virtual Desktop Infrastructure
- Attack Vector
- Local
- Attack Complexity
- Low
- Privileges Required
- Low
- User Interaction
- None
- CWE Classification
- CWE-73