Vulnerability Description
A client-side authorization flaw in Lightspeed Classroom v5.1.2.1763770643 allows unauthenticated attackers to impersonate users by bypassing integrity checks and abusing client-generated authorization tokens, leading to unauthorized control and monitoring of student devices.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://tasty-hovercraft-9b9.notion.site/Enabling-Unauthorized-Remote-Control-of
- https://www.incognitotgt.me/blog/lightspeed
- https://github.com/truekas/ls-poc
- https://tasty-hovercraft-9b9.notion.site/Enabling-Unauthorized-Remote-Control-of
FAQ
What is CVE-2026-30368?
CVE-2026-30368 is a vulnerability with a CVSS score of 5.4 (MEDIUM). A client-side authorization flaw in Lightspeed Classroom v5.1.2.1763770643 allows unauthenticated attackers to impersonate users by bypassing integrity checks and abusing client-generated authorizatio...
How severe is CVE-2026-30368?
CVE-2026-30368 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-30368?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.