Microsoft has disclosed CVE-2026-62896, a CVSS 9.6 improper authentication flaw in Microsoft Teams that lets an authenticated attacker escalate privileges across a network with no user interaction.
What Is It
CVE-2026-62896 is an improper authentication vulnerability (CWE-287) in Microsoft Teams. Per the NVD record, the flaw "allows an authorized attacker to elevate privileges over a network." Microsoft ([email protected]) is the assigning source, and the record currently carries a status of Received; meaning NVD analysis is still in progress.
The issue carries a CVSS 3.1 base score of 9.6 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N. The critical rating is driven by a changed scope (S:C) combined with high confidentiality and integrity impact.
Why It Matters
The attack profile is unusually favorable to an attacker. It is network-reachable (AV:N), low complexity (AC:L), and requires no user interaction (UI:N). The only barrier is low-level privileges (PR:L), meaning any account with basic authenticated access to the affected service is a viable starting point.
Scope is marked Changed, so a successful exploit affects resources beyond the vulnerable component itself. SSVC decision-point data accompanying the record rates technical impact as total, with exploitation scored as "none" and automatable as "no"; figures drawn from the vulnerability record as supplied, not independently confirmed against CISA's published assessment.
There is no confirmation of active exploitation. CVE-2026-62896 is not listed in the CISA Known Exploited Vulnerabilities catalog as of catalog version 2026.08.06 (released 2026-08-06, 1,661 entries), verified directly against CISA's published feed rather than inferred from its absence in the vulnerability record. Because it is not a KEV entry, no BOD 22-01 remediation deadline applies to it. KEV status can change on any catalog update, so federal civilian agencies and organizations that track KEV contractually should re-check the feed rather than treat this as permanent.
What's Vulnerable
Microsoft lists the affected product as Microsoft Teams, with the version field recorded as "-" (all versions / not version-specific). No affected CPE entries are present in the record.
The CVE is tagged exclusively-hosted-service, indicating the vulnerability exists in Microsoft's hosted infrastructure rather than in customer-installed software.
Patch Status
Because this is an exclusively hosted service, remediation is handled by Microsoft on the service side rather than through a customer-applied patch. No specific required action or due date is supplied in the source data. Consult the Microsoft Security Response Center advisory for current mitigation guidance.
Sources
- NVD, CVE-2026-62896: https://nvd.nist.gov/vuln/detail/CVE-2026-62896
- Microsoft MSRC Update Guide: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62896
- CISA Known Exploited Vulnerabilities Catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog