Description
Origin validation error in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.
Published: 2026-09-08
Score: 5.8 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Microsoft Teams for Android originates from an origin validation error that permits an authorized attacker to expose private data across the network. This weakness, classified as CWE-346, allows accidental leakage of application information when network requests or responses are not properly checked. The impact is a partial compromise of confidentiality, potentially revealing sensitive organizational or user data without altering the system’s stability.

Affected Systems

Affected system is Microsoft Teams for Android, across all currently released versions as specific version numbers are not enumerated in the advisory. The product is available for Android devices, and Microsoft has issued the vulnerability notice for the general app, not tied to a particular tier or deployment.

Risk and Exploitability

The CVSS score of 5.8 indicates a medium severity. With no EPSS data and not listed in the KEV catalog, the exploitation probability is uncertain but the risk remains that an attacker who has legitimate Teams access could leverage network traffic to glean information. The attack vector is likely through intercepted or manipulated Teams network traffic, and mitigation depends on applying the vendor‑released patch or update.

Generated by OpenCVE AI on September 8, 2026 at 22:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft Teams for Android patch that addresses the origin validation flaw
  • Check for the update through Google Play or the Microsoft Store and install immediately
  • Configure device security policies to restrict the Teams app’s network permissions and monitor for unexpected data exfiltration patterns

Generated by OpenCVE AI on September 8, 2026 at 22:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Origin validation error in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.
Title Microsoft Teams for Android Information Disclosure Vulnerability
First Time appeared Microsoft
Microsoft teams
Weaknesses CWE-346
CPEs cpe:2.3:a:microsoft:teams:*:*:*:*:*:android:*:*
Vendors & Products Microsoft
Microsoft teams
References
Metrics cvssV3_1

{'score': 5.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:N/A:N/E:U/RL:O/RC:C'}


cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-08T23:40:30.652Z

Reserved: 2026-08-03T21:15:56.835Z

Link: CVE-2026-69559

cve-icon Vulnrichment

Updated: 2026-09-08T20:07:30.304Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T18:19:24.600

Modified: 2026-09-08T20:17:52.193

Link: CVE-2026-69559

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T22:45:16Z

Weaknesses