CVE-2025-26643

CVSS v3 Score
5.4
Medium

Vulnerability Description

The UI performs the wrong action in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

CVSS:4.4(Medium)

Improper authentication in some Zoom clients may allow a privileged user to conduct a disclosure of information via local access.

CVSS:6.5(Medium)

Client-side enforcement of server-side security in Zoom clients before 5.14.10 may allow an authenticated user to enable information disclosure via network access.

CVSS:6.5(Medium)

Improper input validation in Zoom Desktop Client for Windows before 5.15.5 may allow an authenticated user to enable an information disclosure via network access.

CVSS:6.5(Medium)

Improper authentication in Zoom clients may allow an authenticated user to conduct a denial of service via network access.

CVSS:6.5(Medium)

Improper access control in Zoom Mobile App for iOS and Zoom SDKs for iOS before version 5.16.5 may allow an authenticated user to conduct a disclosure of information via network access.

CVSS:6.5(Medium)

Insufficient control flow management in some Zoom clients may allow an authenticated user to conduct an information disclosure via network access.