Description
Exposure of sensitive information to an unauthorized actor in Microsoft Teams Mobile allows an unauthorized attacker to disclose information over a network.
Published: 2026-08-11
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthorized attacker can learn sensitive data from the Microsoft Teams iOS application, as the vulnerability allows disclosure of information over a network. The flaw represents an instance of information disclosure (CWE-200), meaning that personal or confidential data may be leaked while the app is operating on a mobile device.

Affected Systems

Microsoft Teams for iOS is affected; specific build numbers are not listed, so any installed version of the Teams mobile client could potentially be susceptible until the vendor releases an updated application.

Risk and Exploitability

The CVSS score of 6.5 indicates a medium severity vulnerability, and the EPSS score is not available, so the probability of exploitation is unclear. The CVE is not listed under the CISA KEV catalog, suggesting no known large‑scale deployments of active exploits. The likely attack vector is over the network because the disclosure occurs when the app communicates with Microsoft’s servers, but this is inferred from the description and not explicitly documented.

Generated by OpenCVE AI on August 12, 2026 at 12:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Microsoft Teams for iOS to the latest version available in the App Store to obtain the vendor‑supplied fix.
  • If an immediate update is unavailable, uninstall the current Teams client and refrain from using the application until the patch is released to avoid potential data leakage.
  • While awaiting the patch, use a mobile device management or network policy solution to block or quarantine Teams app traffic, preventing potential information disclosure over the network until the vulnerability is addressed.

Generated by OpenCVE AI on August 12, 2026 at 12:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 11 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description Exposure of sensitive information to an unauthorized actor in Microsoft Teams Mobile allows an unauthorized attacker to disclose information over a network.
Title Microsoft Teams iOS Information Disclosure Vulnerability
First Time appeared Microsoft
Microsoft teams
Weaknesses CWE-200
CPEs cpe:2.3:a:microsoft:teams:*:*:*:*:*:iphone_os:*:*
Vendors & Products Microsoft
Microsoft teams
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C'}


cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-31T20:06:00.934Z

Reserved: 2026-07-22T21:30:09.118Z

Link: CVE-2026-65769

cve-icon Vulnrichment

Updated: 2026-08-11T20:38:13.997Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T17:18:56.240

Modified: 2026-08-16T17:17:30.873

Link: CVE-2026-65769

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T12:45:02Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor