Zoom On-Premise Deployments: Improper Access Control
Description
Zoom On-Premise Meeting Connector MMR before version 4.8.20220815.130 contains an improper access control vulnerability. As a result, a malicious actor could obtain the audio and video feed of a meeting they were not authorized to join and cause other meeting disruptions.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
An improper access control vulnerability in Zoom On-Premise Meeting Connector MMR before 4.8.20220815.130 allows unauthorized access to meeting audio/video feeds.
Vulnerability
Zoom On-Premise Meeting Connector MMR before version 4.8.20220815.130 contains an improper access control vulnerability [1]. The flaw exists in the meeting management component such that a malicious actor could gain access to meeting audio and video feeds without proper authorization.
Exploitation
An attacker does not require any special authentication or privileges beyond network access to the affected Zoom On-Premise Meeting Connector MMR server [1]. By exploiting the improper access control, the attacker can intercept the audio and video streams of meetings they were not authorized to join.
Impact
Successful exploitation allows the attacker to obtain the audio and video feed of meetings they were not authorized to attend, and may also enable other meeting disruptions [1]. This leads to a compromise of confidentiality of meeting content and potential integrity/availability impacts.
Mitigation
The vulnerability is fixed in Zoom On-Premise Meeting Connector MMR version 4.8.20220815.130 [1]. Users should update to this version or later to mitigate the issue. No workarounds are mentioned in the available references.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <4.8.20220815.130
- Range: unspecified
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- explore.zoom.us/en/trust/security/security-bulletin/mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.