Description
Improper authorization in Microsoft Teams allows an authorized attacker to disclose information over a network.
Published: 2026-05-07
Score: 9.6 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper authorization flaw enables an attacker who already has legitimate access to Microsoft Teams to read sensitive data that should be protected. The vulnerability allows the disclosure of information over the network, compromising confidentiality and potentially exposing internal communications or event details.

Affected Systems

The vulnerability affects Microsoft Teams. No specific versions or patches are listed in the data, so all current deployments of Teams are considered potentially vulnerable until a patch is applied.

Risk and Exploitability

The CVSS score of 9.6 classifies this issue as critical, indicating a high likelihood of successful exploitation and severe impact. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The description that the attacker must be authorized and can retrieve data over a network implies that the attack vector is remote network traffic. This inference is drawn from the statement that the flaw allows an authorized attacker to disclose information over a network.

Generated by OpenCVE AI on May 7, 2026 at 22:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft Teams update that contains the fix for improper authorization in the event portal.
  • Restrict network access to the Teams Event Portal by limiting connections to approved IP ranges or internal networks.
  • Enforce strict role‑based access controls so that only users who truly need to view event portal data can be granted the necessary permissions.

Generated by OpenCVE AI on May 7, 2026 at 22:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 07 May 2026 21:30:00 +0000

Type Values Removed Values Added
Description Improper authorization in Microsoft Teams allows an authorized attacker to disclose information over a network.
Title Microsoft Team Events Portal Information Disclosure Vulnerability
First Time appeared Microsoft
Microsoft teams
Weaknesses CWE-285
CPEs cpe:2.3:a:microsoft:teams:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft teams
References
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N/E:U/RL:O/RC:C'}


cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-05-07T20:58:52.175Z

Reserved: 2026-03-24T00:52:01.351Z

Link: CVE-2026-33823

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-05-07T22:16:34.283

Modified: 2026-05-07T22:16:34.283

Link: CVE-2026-33823

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-08T00:30:25Z

Weaknesses