PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-39653 Deepen Bajracharya CVE debrief

A Missing Authorization vulnerability in Deepen Bajracharya's Video Conferencing with Zoom plugin allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Video Conferencing with Zoom from n/a through <= 4.6.6. The vulnerability has a CVSS score of 4.3 and is classified as MEDIUM severity. The vulnerability is related to a Missing Authorization issue in the Video Conferencing with Zoom plugin. Users of Video Conferencing with Zoom plugin versions up to 4.6.6 should verify their installation and update to a patched version if available. The CVE record was published on 2026-04-08T09:16:36.457Z and was last modified on 2026-07-24T21:10:00.143Z.

Vendor
Deepen Bajracharya
Product
Video Conferencing with Zoom
CVSS
MEDIUM 4.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-08
Original CVE updated
2026-07-24
Advisory published
2026-04-08
Advisory updated
2026-07-24

Who should care

Users of Video Conferencing with Zoom plugin versions up to 4.6.6 should verify their installation and update to a patched version if available. The vulnerability affects Video Conferencing with Zoom plugin versions up to 4.6.6. The CVE-2026-39653 vulnerability has a CVSS score of 4.3 and is classified as MEDIUM severity.

Technical summary

The CVE-2026-39653 vulnerability has a CVSS score of 4.3 and is classified as MEDIUM severity. It was published on 2026-04-08T09:16:36.457Z and last modified on 2026-07-24T21:10:00.143Z. The vulnerability is related to a Missing Authorization issue in the Video Conferencing with Zoom plugin. This issue affects Video Conferencing with Zoom from n/a through <= 4.6.6. Users should verify their installation and update to a patched version if available.

Defensive priority

Medium priority due to the potential for exploiting incorrectly configured access control security levels.

Recommended defensive actions

  • Verify the current version of Video Conferencing with Zoom plugin and update to a patched version if available.
  • Review and adjust access control configurations to prevent exploitation of incorrectly configured security levels.
  • Monitor plugin updates and security advisories for further information.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.

Evidence notes

The CVE record was published on 2026-04-08T09:16:36.457Z and was last modified on 2026-07-24T21:10:00.143Z. The NVD entry is currently Deferred. The vulnerability affects Video Conferencing with Zoom plugin versions up to 4.6.6. Users should verify their installation and update to a patched version if available. The CVE-2026-39653 vulnerability has a CVSS score of 4.3 and is classified as MEDIUM severity. The vulnerability is related to a Missing Authorization issue in the Video Conferencing with Zoom plugin. The NVD entry provides additional information on the vulnerability.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-08T09:16:36.457Z and has not been modified since then. The NVD entry is currently Deferred.