Description
Improper authentication in Microsoft Authenticator allows an unauthorized attacker to elevate privileges locally.
Published: 2026-09-08
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Local privilege escalation
Action: Immediate Patch
AI Analysis

Impact

The vulnerability stems from improper authentication within Microsoft Authenticator for Android, allowing an unauthorized local attacker to elevate privileges. This flaw enables the attacker to bypass standard security controls and gain elevated access to the device, potentially compromising confidential data, executing privileged actions, and furthering other attacks. The weakness is classified as improper authentication and can lead to unauthorized system access and privilege abuse.

Affected Systems

Microsoft Authenticator for Android is affected. No specific version information is provided, indicating that all released versions prior to the official fix are vulnerable. The issue affects all installations of the app that have not been updated to the patched release.

Risk and Exploitability

With a CVSS score of 8.6 the flaw is considered high severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is inferred to be local, requiring the attacker to have physical or otherwise privileged access to the device. Once the flaw is exploited, the attacker can acquire local administrative rights, posing a significant risk to device integrity and confidentiality.

Generated by OpenCVE AI on September 9, 2026 at 04:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Microsoft Authenticator to the latest version available on Google Play to receive the security fix.
  • If an update cannot be applied immediately, consider removing or disabling the app until the patch is available to eliminate the vulnerability surface.
  • Enforce device-level security controls such as multi‑factor authentication, strict app permissions, and regular security audits to detect and prevent unauthorized privilege escalation.

Generated by OpenCVE AI on September 9, 2026 at 04:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:microsoft:authenticator:*:*:*:*:*:android:*:*

Thu, 10 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft authenticator For Android
Vendors & Products Microsoft authenticator For Android

Wed, 09 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Improper authentication in Microsoft Authenticator allows an unauthorized attacker to elevate privileges locally.
Title Microsoft Authenticator Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft authenticator
Weaknesses CWE-287
CPEs cpe:2.3:a:microsoft:authenticator:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft authenticator
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Authenticator Authenticator For Android
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:33:49.195Z

Reserved: 2026-08-25T18:37:59.830Z

Link: CVE-2026-80097

cve-icon Vulnrichment

Updated: 2026-09-09T10:00:01.100Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:20:52.137

Modified: 2026-09-24T12:59:50.470

Link: CVE-2026-80097

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T08:00:06Z

Weaknesses