PatchSiren cyber security CVE debrief
CVE-2026-39653 Deepen Bajracharya CVE debrief
A Missing Authorization vulnerability in Deepen Bajracharya's Video Conferencing with Zoom plugin allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Video Conferencing with Zoom from n/a through <= 4.6.6. The vulnerability has a CVSS score of 4.3 and is classified as MEDIUM severity. The vulnerability is related to a Missing Authorization issue in the Video Conferencing with Zoom plugin. Users of Video Conferencing with Zoom plugin versions up to 4.6.6 should verify their installation and update to a patched version if available. The CVE record was published on 2026-04-08T09:16:36.457Z and was last modified on 2026-07-24T21:10:00.143Z.
- Vendor
- Deepen Bajracharya
- Product
- Video Conferencing with Zoom
- CVSS
- MEDIUM 4.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-08
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-04-08
- Advisory updated
- 2026-07-24
Who should care
Users of Video Conferencing with Zoom plugin versions up to 4.6.6 should verify their installation and update to a patched version if available. The vulnerability affects Video Conferencing with Zoom plugin versions up to 4.6.6. The CVE-2026-39653 vulnerability has a CVSS score of 4.3 and is classified as MEDIUM severity.
Technical summary
The CVE-2026-39653 vulnerability has a CVSS score of 4.3 and is classified as MEDIUM severity. It was published on 2026-04-08T09:16:36.457Z and last modified on 2026-07-24T21:10:00.143Z. The vulnerability is related to a Missing Authorization issue in the Video Conferencing with Zoom plugin. This issue affects Video Conferencing with Zoom from n/a through <= 4.6.6. Users should verify their installation and update to a patched version if available.
Defensive priority
Medium priority due to the potential for exploiting incorrectly configured access control security levels.
Recommended defensive actions
- Verify the current version of Video Conferencing with Zoom plugin and update to a patched version if available.
- Review and adjust access control configurations to prevent exploitation of incorrectly configured security levels.
- Monitor plugin updates and security advisories for further information.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
The CVE record was published on 2026-04-08T09:16:36.457Z and was last modified on 2026-07-24T21:10:00.143Z. The NVD entry is currently Deferred. The vulnerability affects Video Conferencing with Zoom plugin versions up to 4.6.6. Users should verify their installation and update to a patched version if available. The CVE-2026-39653 vulnerability has a CVSS score of 4.3 and is classified as MEDIUM severity. The vulnerability is related to a Missing Authorization issue in the Video Conferencing with Zoom plugin. The NVD entry provides additional information on the vulnerability.
Official resources
-
CVE-2026-39653 CVE record
CVE.org
-
CVE-2026-39653 NVD detail
NVD
-
Source item URL
nvd_modified
- Mitigation or vendor reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-08T09:16:36.457Z and has not been modified since then. The NVD entry is currently Deferred.