SYS::ONLINE
Wasteland.
Briefs1769
Issues22
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-62896 2026-08-06

CVE-2026-62896: Critical Privilege Escalation in Microsoft Teams

"Microsoft has disclosed CVE-2026-62896, a CVSS 9.6 improper authentication flaw in Microsoft Teams that lets an authenticated attacker escalate privileges across a network with no user interaction."

Microsoft has disclosed CVE-2026-62896, a CVSS 9.6 improper authentication flaw in Microsoft Teams that lets an authenticated attacker escalate privileges across a network with no user interaction.

What Is It

CVE-2026-62896 is an improper authentication vulnerability (CWE-287) in Microsoft Teams. Per the NVD record, the flaw "allows an authorized attacker to elevate privileges over a network." Microsoft ([email protected]) is the assigning source, and the record currently carries a status of Received; meaning NVD analysis is still in progress.

The issue carries a CVSS 3.1 base score of 9.6 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N. The critical rating is driven by a changed scope (S:C) combined with high confidentiality and integrity impact.

Why It Matters

The attack profile is unusually favorable to an attacker. It is network-reachable (AV:N), low complexity (AC:L), and requires no user interaction (UI:N). The only barrier is low-level privileges (PR:L), meaning any account with basic authenticated access to the affected service is a viable starting point.

Scope is marked Changed, so a successful exploit affects resources beyond the vulnerable component itself. SSVC decision-point data accompanying the record rates technical impact as total, with exploitation scored as "none" and automatable as "no"; figures drawn from the vulnerability record as supplied, not independently confirmed against CISA's published assessment.

There is no confirmation of active exploitation. CVE-2026-62896 is not listed in the CISA Known Exploited Vulnerabilities catalog as of catalog version 2026.08.06 (released 2026-08-06, 1,661 entries), verified directly against CISA's published feed rather than inferred from its absence in the vulnerability record. Because it is not a KEV entry, no BOD 22-01 remediation deadline applies to it. KEV status can change on any catalog update, so federal civilian agencies and organizations that track KEV contractually should re-check the feed rather than treat this as permanent.

What's Vulnerable

Microsoft lists the affected product as Microsoft Teams, with the version field recorded as "-" (all versions / not version-specific). No affected CPE entries are present in the record.

The CVE is tagged exclusively-hosted-service, indicating the vulnerability exists in Microsoft's hosted infrastructure rather than in customer-installed software.

Patch Status

Because this is an exclusively hosted service, remediation is handled by Microsoft on the service side rather than through a customer-applied patch. No specific required action or due date is supplied in the source data. Consult the Microsoft Security Response Center advisory for current mitigation guidance.

Sources