CVE-2026-30368

Lightspeed Classroom 5.1.2.1763770643 - Auth Bypass

Title source: llm

Description

A client-side authorization flaw in Lightspeed Classroom v5.1.2.1763770643 allows unauthenticated attackers to impersonate users by bypassing integrity checks and abusing client-generated authorization tokens, leading to unauthorized control and monitoring of student devices.

Exploits (1)

github WORKING POC 12 stars
by truekas · javascriptpoc
https://github.com/truekas/ls-poc

Details

Status published
Published Apr 24, 2026
Tracked Since Apr 24, 2026