{"id":"CVE-2026-30368","title":"A client-side authorization flaw in Lightspeed Systems Classroom v5.1.2.1763770643 allows unauthenticated attackers to impersonate users by bypassing integrity checks and abusing client-generated authorization tokens, leading to unauthor…","summary":"A client-side authorization flaw in Lightspeed Systems Classroom v5.1.2.1763770643 allows unauthenticated attackers to impersonate users by bypassing integrity checks and abusing client-generated authorization tokens, leading to unauthor…","severity":"medium","cvss":5.4,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N","cwe":["CWE-863"],"vendor":"Lightspeed","product":"Lightspeed Classroom","affected":["classroom 5.1.2.1763770643"],"published":"2026-04-24","updated":"2026-09-08","sourceUpdated":"2026-09-08T19:17:57.183","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-30368","references":[{"url":"https://tasty-hovercraft-9b9.notion.site/Enabling-Unauthorized-Remote-Control-of-Student-Devices-with-Lightspeed-Classroom-2ec5157f5b4a800c9eefc5526479820a","label":"cve@mitre.org"},{"url":"https://truekas.dev/blog/lightspeed","label":"cve@mitre.org"},{"url":"https://www.incognitotgt.me/blog/lightspeed","label":"cve@mitre.org"},{"url":"https://www.lightspeedsystems.com/products/lightspeed-classroom-management/","label":"cve@mitre.org"},{"url":"https://github.com/truekas/ls-poc","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://tasty-hovercraft-9b9.notion.site/Enabling-Unauthorized-Remote-Control-of-Student-Devices-with-Lightspeed-Classroom-2ec5157f5b4a800c9eefc5526479820a","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","cve.org","exploit-available"],"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"no","technicalImpact":"partial","timestamp":"2026-04-27T10:17:22.860099Z"},"epss":0.00353,"epssPercentile":0.28987,"exploits":{"github":1,"githubRepos":["https://github.com/truekas/ls-poc"],"checkedAt":"2026-09-21T15:28:38.771Z"},"ingestedAt":"2026-09-08T19:08:49.637Z","slug":"CVE-2026-30368","body":"## Overview\n\nA client-side authorization flaw in Lightspeed Systems Classroom v5.1.2.1763770643 allows unauthenticated attackers to impersonate users by bypassing integrity checks and abusing client-generated authorization tokens, leading to unauthorized control and monitoring of student devices.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":42,"depthScoreParts":{"impact":29.7,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[]}