Impact
Microsoft Teams suffers from an improper authentication flaw that enables an attacker with legitimate credentials to increase their privileges within the network. The vulnerability can lead to unauthorized access to sensitive information and control over the Teams environment. The weakness corresponds to CWE-287, which applies to broken access control that allows attackers to bypass authentication checks.
Affected Systems
Any installation of Microsoft Teams that has not yet applied the security update addressing CVE-2026‑62896 is at risk. The vendor specifies Microsoft Teams as the affected product but does not list specific version numbers, so the flaw applies to all current releases until the patch is deployed.
Risk and Exploitability
The CVSS score of 9.6 marks the vulnerability as critical, indicating that its exploitation can have a major impact on confidentiality, integrity, and availability. The EPSS score is not available, so the exact likelihood of exploitation cannot be quantified, but the absence of a KEV listing suggests no known exploit has yet been observed in the wild. The likely attack vector is an authorized user or compromised account on the same network, and the flaw requires only a bearer of valid credentials to elevate privileges.
OpenCVE Enrichment