• PATCH AVAILABLE

CVE-2026-65667: missing authorization in Microsoft Microsoft Teams

An unauthenticated network attacker can elevate privileges in Microsoft Teams, potentially gaining high-impact access to data and functionality. CVE-2026-65667 permits privilege elevation without prior authentication or user interaction; affected entries are listed under the Microsoft Teams branch, and vendor fixed-version details are not included in the provided facts. An attacker only needs network access to target Teams services to exploit the missing authorization flaw.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
10CRITICAL
EPSS
0.00798
CWE
CWE-862
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: this flaw requires no authentication, so exposed Teams services are at high risk; prioritize applying vendor updates or mitigations immediately because an unauthenticated attacker can trigger privilege elevation.

What is CVE-2026-65667?

An unauthenticated network attacker can elevate privileges in Microsoft Teams, potentially gaining high-impact access to data and functionality. CVE-2026-65667 permits privilege elevation without prior authentication or user interaction; affected entries are listed under the Microsoft Teams branch, and vendor fixed-version details are not included in the provided facts. An attacker only needs network access to target Teams services to exploit the missing authorization flaw.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

Which versions of Microsoft Microsoft Teams are affected?

BRANCHAFFECTEDFIXED
Microsoft Teams-

Is CVE-2026-65667 being exploited?

There are no public reports of exploitation of this vulnerability as of 2026-09-29.

How to fix CVE-2026-65667

  1. Apply Microsoft Teams updates and guidance provided by Microsoft as soon as they are available.
  2. Restrict network exposure of Teams services to trusted networks and use access controls or VPNs where possible.
  3. Monitor Teams logs and identity/privilege changes for suspicious activity and anomalous account elevations.
  4. Follow Microsoft's mitigation recommendations and keep endpoint and identity protections up to date.

Frequently asked questions

Is CVE-2026-65667 being actively exploited?

There are no public reports of active exploitation of CVE-2026-65667 as of 2026-09-29.

Which Microsoft Teams versions are affected by CVE-2026-65667?

The provided facts list the Microsoft Teams branch as affected but do not specify exact product versions or build numbers that are impacted or fixed.

Is there a patch for CVE-2026-65667?

Patch availability is indicated; apply the updates and guidance Microsoft published for Microsoft Teams to remediate the issue.

Does CVE-2026-65667 require authentication?

No. The flaw is a missing authorization vulnerability that can be triggered without prior authentication or user interaction against Microsoft Teams.

References