DIRAS TAKE
Urgent: this flaw requires no authentication, so exposed Teams services are at high risk; prioritize applying vendor updates or mitigations immediately because an unauthenticated attacker can trigger privilege elevation.
What is CVE-2026-65667?
An unauthenticated network attacker can elevate privileges in Microsoft Teams, potentially gaining high-impact access to data and functionality. CVE-2026-65667 permits privilege elevation without prior authentication or user interaction; affected entries are listed under the Microsoft Teams branch, and vendor fixed-version details are not included in the provided facts. An attacker only needs network access to target Teams services to exploit the missing authorization flaw.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Which versions of Microsoft Microsoft Teams are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| Microsoft Teams | - |
Is CVE-2026-65667 being exploited?
There are no public reports of exploitation of this vulnerability as of 2026-09-29.
How to fix CVE-2026-65667
- Apply Microsoft Teams updates and guidance provided by Microsoft as soon as they are available.
- Restrict network exposure of Teams services to trusted networks and use access controls or VPNs where possible.
- Monitor Teams logs and identity/privilege changes for suspicious activity and anomalous account elevations.
- Follow Microsoft's mitigation recommendations and keep endpoint and identity protections up to date.
Frequently asked questions
Is CVE-2026-65667 being actively exploited?
There are no public reports of active exploitation of CVE-2026-65667 as of 2026-09-29.
Which Microsoft Teams versions are affected by CVE-2026-65667?
The provided facts list the Microsoft Teams branch as affected but do not specify exact product versions or build numbers that are impacted or fixed.
Is there a patch for CVE-2026-65667?
Patch availability is indicated; apply the updates and guidance Microsoft published for Microsoft Teams to remediate the issue.
Does CVE-2026-65667 require authentication?
No. The flaw is a missing authorization vulnerability that can be triggered without prior authentication or user interaction against Microsoft Teams.
References
- nvd.nist.gov/vuln/detail/CVE-2026-65667
- cve.org/CVERecord?id=CVE-2026-65667
- msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65667
- All Microsoft CVEs on CVE Radar
- CVEs published in September 2026