Description
Insertion of sensitive information into sent data in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.
Published: 2026-09-08
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Patch Now
AI Analysis

Impact

Microsoft Teams for Android may insert sensitive information into outgoing data packets. This flaw allows an authorized attacker who can trigger data transmission to capture and read confidential content. The vulnerability relies on improper handling of data before network transport and is categorized as CWE-201, a weakness that exposes sensitive information.

Affected Systems

The flaw affects Microsoft Teams for Android deployments. Users running any instance of the Microsoft Teams Android app are potentially exposed; no specific sub‑version list is provided, so all versions remain at risk until updated.

Risk and Exploitability

The CVSS score of 6.8 indicates a medium severity risk. While the EPSS score is not available, the lack of a KEV listing suggests limited known exploitation. The attack likely requires the victim to be using Teams and to engage in normal data transmission, making exploitation possible within typical user activity but not requiring advanced privileges.

Generated by OpenCVE AI on September 8, 2026 at 18:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft Teams for Android update from the official app store or Microsoft update portal
  • Restrict the transmission of any sensitive data within Teams to only necessary recipients and over secure channels
  • Enforce end‑to‑end encryption and verify that all network traffic from Teams uses TLS or a VPN to mitigate potential packet capture

Generated by OpenCVE AI on September 8, 2026 at 18:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Insertion of sensitive information into sent data in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.
Title Microsoft Teams for Android Information Disclosure Vulnerability
First Time appeared Microsoft
Microsoft teams
Weaknesses CWE-201
CPEs cpe:2.3:a:microsoft:teams:*:*:*:*:*:android:*:*
Vendors & Products Microsoft
Microsoft teams
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N/E:U/RL:O/RC:C'}


cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:37:35.155Z

Reserved: 2026-07-22T21:36:47.630Z

Link: CVE-2026-65812

cve-icon Vulnrichment

Updated: 2026-09-08T20:05:18.849Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T18:18:18.520

Modified: 2026-09-15T18:17:30.897

Link: CVE-2026-65812

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T20:00:12Z

Weaknesses
  • CWE-201

    Insertion of Sensitive Information Into Sent Data