CVE-2026-30368 is a client-side authorization vulnerability in Lightspeed Systems Classroom version 5.1.2.1763770643. An unauthenticated attacker can bypass client-side integrity checks and abuse client-generated authorization tokens to impersonate users. The flaw enables unauthorized interaction with Classroom-managed student devices, including device control and monitoring.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a functional proof-of-concept exploit for CVE-2026-30368 affecting Lightspeed Classroom. It is not a framework module; it consists of a README with detailed operator instructions, a small main exploit script (poc.js), and a larger helper/emulation loader (wasm-loader.js). Repository structure and purpose: - README.md: Operational guide. It explains the vulnerability, required external files, how to patch the vendor worker, how JWT extraction works, and how to use the resulting Ably channel access for command delivery and optional WebRTC/video signaling. - poc.js: Main operator script. It calls runServiceWorker() from wasm-loader.js to extract a JWT, kills the emulated worker, exchanges the JWT with Lightspeed's Ably-related API endpoint, then creates an Ably Realtime client, connects to a victim-specific channel (${cId}:${email}), subscribes to messages, and provides a helper to publish commands/messages. - wasm-loader.js: Environment-spoofing and execution harness. It emulates enough of a Chrome extension/service worker runtime under Node.js to execute a patched Lightspeed worker locally, including spoofed location/origin, ServiceWorkerGlobalScope, self, importScripts, and related globals. It then evaluates a local patched worker file, triggers install/activate handlers, and polls global state for the extracted JWT. Main exploit capabilities: 1. Local execution of a patched Lightspeed Classroom service worker outside the browser by spoofing the extension/service-worker environment. 2. Extraction of a JWT generated by the extension's classroom.wasm logic. 3. Exchange of that JWT for an Ably authentication token via https://ably.lightspeedsystems.app. 4. Connection to the target's Ably realtime channel using the victim identifiers email and cId. 5. Ability to subscribe to channel traffic and publish messages/commands to the student device channel. 6. README-documented extension to initiate WebRTC signaling over the same channel for viewer/video access. Notable implementation details: - The exploit is operational but requires manual preparation: the operator must obtain district/version-specific extension files (worker.js, classroom.wasm, manifest.json), patch the worker, set the extension ID, and recover the API key from the extension source. - The code is clearly offensive rather than merely diagnostic; it aims to gain control over a student's device messaging channel. - The PoC does not include the vendor files themselves, so exploitation depends on external acquisition and customization. - Because the payload is basic and partly hardcoded/manual rather than fully generalized, OPERATIONAL is the best maturity fit.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.