Description
Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
Published: 2026-09-08
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Security Feature Bypass over a network
Action: Immediate Patch
AI Analysis

Impact

Visual Studio Code does not enforce a required security policy, allowing an attacker to circumvent a built‑in protection when accessed across a network. The flaw can lead to unauthorized execution or data exposure depending on the function that is bypassed. Because the failure is of type "failing open", the impacted system will automatically grant the attacker the privilege that the policy would normally restrict, raising confidentiality and integrity risks.

Affected Systems

The vulnerability belongs to Microsoft Visual Studio Code. No specific version information is listed, so all installations that may still contain the unpatched code could be susceptible.

Risk and Exploitability

The CVSS score of 8.2 indicates a high severity, and the EPSS score, while not reported, does not adjust the perception of risk. The vulnerability is not currently included in the CISA KEV catalog. The attack vector is inferred to be over a network, as the description states that the bypass can occur via a network connection. An attacker would need to reach the affected workstation or server running VS Code to exploit the flaw.

Generated by OpenCVE AI on September 9, 2026 at 04:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Visual Studio Code release to include the vendor patch
  • If an update cannot be performed immediately, disable or restrict the network access method that triggers the vulnerable feature
  • Continuously monitor application logs and network activity for signs of unauthorized access attempts

Generated by OpenCVE AI on September 9, 2026 at 04:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:microsoft:visual_studio_code:*:*:*:*:*:-:*:*

Thu, 10 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
Title Visual Studio Code Security Feature Bypass Vulnerability
First Time appeared Microsoft
Microsoft visual Studio Code
Weaknesses CWE-636
CPEs cpe:2.3:a:microsoft:visual_studio_code:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft visual Studio Code
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Visual Studio Code
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:33:53.368Z

Reserved: 2026-08-26T18:46:26.214Z

Link: CVE-2026-81379

cve-icon Vulnrichment

Updated: 2026-09-10T14:32:28.044Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:20:54.193

Modified: 2026-09-11T21:08:42.490

Link: CVE-2026-81379

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T05:45:06Z

Weaknesses
  • CWE-636

    Not Failing Securely ('Failing Open')