Description
Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.
Published: 2026-08-06
Score: 10 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Missing authorization in Microsoft Teams allows an attacker without proper credentials to elevate privileges across the network. The flaw enables unauthorized users to attain higher level access, potentially compromising confidential data and disrupting services. This weakness is a classic Missing Authorization problem as identified by CWE‑862.

Affected Systems

The vulnerability affects Microsoft Teams, all versions distributed by Microsoft. No specific version range is listed, so administrators should treat all deployed Teams installations as potentially vulnerable until a patch is applied.

Risk and Exploitability

The CVSS score of 10 signals a critical severity. With no EPSS score available, the exploitation probability is unknown, but the lack of a KEV listing does not negate the risk. The attack can be launched from any remote network location where the attacker can interact with the Teams application, making the potential impact wide‑spread if exploited. Immediate patching mitigates the risk of privilege escalation and related data breaches.

Generated by OpenCVE AI on August 7, 2026 at 01:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft Teams update that addresses the missing authorization flaw.
  • Restrict network access to Teams by ensuring only authenticated and authorized traffic can reach it, using firewall rules or network segmentation.
  • Review and tighten Teams' role and permission configurations to prevent privileged actions where unnecessary.

Generated by OpenCVE AI on August 7, 2026 at 01:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 01:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 07 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Description Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.
Title Microsoft Teams Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft teams
Weaknesses CWE-862
CPEs cpe:2.3:a:microsoft:teams:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft teams
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N/E:U/RL:O/RC:C'}


cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-07T00:52:43.471Z

Reserved: 2026-07-22T18:16:01.897Z

Link: CVE-2026-65667

cve-icon Vulnrichment

Updated: 2026-08-07T00:52:39.673Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T01:30:03Z

Weaknesses