Description
Improper link resolution before file access ('link following') in Microsoft OneDrive allows an authorized attacker to elevate privileges locally.
Published: 2026-08-11
Score: 6.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper link resolution before file access in Microsoft OneDrive for macOS allows a user with local access to elevate privileges. The vulnerability is classified as CWE‑59 and can give the attacker higher privileges on the machine without any external network interaction.

Affected Systems

Microsoft OneDrive for macOS is affected. Any installed version that has not received the Microsoft update addressing CVE‑2026‑65680 should be considered vulnerable until the patch is applied.

Risk and Exploitability

The CVSS score of 6.7 indicates medium severity. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting it is not a known widely exploited threat. The attack requires local user privileges and relies on manipulating link resolution within the OneDrive environment, making it a local privilege escalation scenario with a moderate risk profile.

Generated by OpenCVE AI on August 12, 2026 at 13:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and install the latest Microsoft OneDrive for macOS update that contains the fix for CVE‑2026‑65680.
  • After installing the update, restart the OneDrive application to ensure the patch takes effect.
  • Until the patch is applied, restrict local users from creating or modifying hyperlinks in OneDrive folders to prevent potential exploitation.

Generated by OpenCVE AI on August 12, 2026 at 13:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description Improper link resolution before file access ('link following') in Microsoft OneDrive allows an authorized attacker to elevate privileges locally.
Title Microsoft OneDrive for MacOS Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft .onedrive For Macos
Weaknesses CWE-59
CPEs cpe:2.3:a:microsoft:.onedrive_for_macos:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft .onedrive For Macos
References
Metrics cvssV3_1

{'score': 6.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft .onedrive For Macos
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-12T13:42:11.508Z

Reserved: 2026-07-22T18:16:01.898Z

Link: CVE-2026-65680

cve-icon Vulnrichment

Updated: 2026-08-12T13:37:15.994Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-08-11T18:18:08.277

Modified: 2026-08-12T14:18:29.470

Link: CVE-2026-65680

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T13:45:03Z

Weaknesses
  • CWE-59

    Improper Link Resolution Before File Access ('Link Following')