Zoom On-Premise Deployments: Improper Access Control
Description
Zoom On-Premise Meeting Connector MMR before version 4.8.20220815.130 contains an improper access control vulnerability. As a result, a malicious actor could obtain the audio and video feed of a meeting they were not authorized to join and cause other meeting disruptions.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Improper access control in Zoom On-Premise Meeting Connector MMR before 4.8.20220815.130 allows unauthorized access to meeting audio/video feeds.
Vulnerability
Zoom On-Premise Meeting Connector MMR versions before 4.8.20220815.130 contain an improper access control vulnerability. This allows an unauthorized actor to access meeting audio and video feeds and cause disruptions. The vulnerability exists in the Meeting Connector component handling meeting join requests.
Exploitation
An attacker who can reach the Zoom On-Premise Meeting Connector MMR can exploit the improper access controls to join a meeting without proper authorization. The exact steps involve sending crafted join requests that bypass authorization checks.
Impact
Successful exploitation grants an attacker unauthorized access to the audio and video feeds of meetings. The attacker can also cause other meeting disruptions, such as dropping participants or interfering with meeting controls. The impact is a breach of confidentiality and availability.
Mitigation
Zoom has released version 4.8.20220815.130 of the On-Premise Meeting Connector MMR, which fixes this vulnerability. Users should upgrade to this version or later. No workarounds are documented. [1]
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <4.8.20220815.130
- Range: unspecified
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.