---
id: CVE-2026-53406
title: >-
  Insufficient Verification of Data Authenticity in Remote Control for Zoom
  Contact Center for Windows before version 7.0.0 may allow an authenticated
  user to enable an escalation of privilege via local access.
summary: >-
  Insufficient Verification of Data Authenticity in Remote Control for Zoom
  Contact Center for Windows before version 7.0.0 may allow an authenticated
  user to enable an escalation of privilege via local access.
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-345
published: '2026-06-12'
updated: '2026-06-29'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-53406'
references:
  - url: 'https://www.zoom.com/en/trust/security-bulletin/zsb-26009'
    label: security@zoom.us
tags:
  - nvd
epss: 0.00114
epssPercentile: 0.01314
ingestedAt: '2026-06-29T14:29:18.110Z'
---

## Overview

Insufficient Verification of Data Authenticity in Remote Control for Zoom Contact Center for Windows before version 7.0.0 may allow an authenticated user to enable an escalation of privilege via local access.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
