Impact
The vulnerability in Microsoft Teams for Android originates from an origin validation error that permits an authorized attacker to expose private data across the network. This weakness, classified as CWE-346, allows accidental leakage of application information when network requests or responses are not properly checked. The impact is a partial compromise of confidentiality, potentially revealing sensitive organizational or user data without altering the system’s stability.
Affected Systems
Affected system is Microsoft Teams for Android, across all currently released versions as specific version numbers are not enumerated in the advisory. The product is available for Android devices, and Microsoft has issued the vulnerability notice for the general app, not tied to a particular tier or deployment.
Risk and Exploitability
The CVSS score of 5.8 indicates a medium severity. With no EPSS data and not listed in the KEV catalog, the exploitation probability is uncertain but the risk remains that an attacker who has legitimate Teams access could leverage network traffic to glean information. The attack vector is likely through intercepted or manipulated Teams network traffic, and mitigation depends on applying the vendor‑released patch or update.
OpenCVE Enrichment