Description
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Teams for Android allows an authorized attacker to perform spoofing over a network.
Published: 2026-08-11
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an improper neutralization of input during web page generation, known as cross‑site scripting, in Microsoft Teams for Android. Because the app renders content that can be manipulated by an authorized attacker, the flaw can be used to inject malicious scripts that cause the app to display spoofed user identities or messages. This enables an attacker who has legitimate credentials or access within Teams to deceive other users into believing they are interacting with a different, trusted user or source.

Affected Systems

Microsoft Teams for Android is affected. No specific version information was provided; any installed instance of the app is potentially vulnerable.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity, but the EPSS value is not available, so the exact likelihood of exploitation is uncertain. The vulnerability is not listed in the CISA KEV catalog. It requires an authorized attacker—one who has legitimate access to the Teams app—to exploit the flaw. If exploited, the attacker can perform spoofing over the network, potentially leading to credential theft or other social‑engineering attacks. Updating to a fixed release from Microsoft eliminates the risk and is the recommended solution.

Generated by OpenCVE AI on August 12, 2026 at 12:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Microsoft Teams for Android to the latest release available through the Google Play Store or Apple App Store, which contains the fix for the XSS vulnerability.
  • Enforce multi‑factor authentication and zero‑trust access controls for Teams so that only verified users can access the app, limiting the scope of any attacker that could exploit the script injection flaw.
  • Where possible, configure device management or Teams settings to block the loading of untrusted web content or disable features that allow arbitrary script execution, reducing the risk of successful spoofing if a patch cannot be applied immediately.

Generated by OpenCVE AI on August 12, 2026 at 12:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 16 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Title Microsoft Teams for Android and iOS Spoofing Vulnerability Microsoft Teams for Android Spoofing Vulnerability

Tue, 11 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Teams for Android allows an authorized attacker to perform spoofing over a network.
Title Microsoft Teams for Android and iOS Spoofing Vulnerability
First Time appeared Microsoft
Microsoft teams
Weaknesses CWE-79
CPEs cpe:2.3:a:microsoft:teams:*:*:*:*:*:android:*:*
Vendors & Products Microsoft
Microsoft teams
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-31T20:08:07.710Z

Reserved: 2026-07-22T21:30:09.118Z

Link: CVE-2026-65767

cve-icon Vulnrichment

Updated: 2026-08-11T17:47:01.257Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T17:18:55.997

Modified: 2026-08-16T18:16:45.927

Link: CVE-2026-65767

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T12:30:03Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')