Microsoft disclosed a missing authorization vulnerability in Microsoft Teams that lets an unauthenticated attacker elevate privileges over a network, rating it CVSS 10.0; the maximum possible score.
What Is It
CVE-2026-65667 is a missing authorization weakness (CWE-862) in Microsoft Teams. Per Microsoft's description, the flaw "allows an unauthorized attacker to elevate privileges over a network." The CVE was published on 2026-08-06 and is currently in "Received" status in NVD, meaning analysis is still ongoing and the record's contents may change.
Microsoft tagged the record exclusively-hosted-service, indicating the affected component is a Microsoft-operated cloud service rather than software customers install and patch themselves.
Why It Matters
The CVSS 3.1 base score is 10.0 (CRITICAL), the highest value the scale allows. The vector, CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N, breaks down to a worst-case exploitability profile:
- Network attack vector with low complexity
- No privileges required and no user interaction
- Scope: Changed: impact extends beyond the vulnerable component
- High confidentiality and integrity impact (availability unaffected)
That yields an exploitability subscore of 3.9, the maximum. CISA's SSVC assessment reinforces the concern: exploitation is currently rated none (no known exploitation observed), but the flaw is marked automatable: yes with technical impact: total.
What's Vulnerable
Microsoft lists the affected product as Microsoft Teams with version status "-" (affected), and no CPE entries are enumerated in the NVD record. Because this is flagged as an exclusively hosted service, no specific client version boundaries are provided in the source data.
Patch Status
As of 2026-08-06, CVE-2026-65667 was not listed in the CISA Known Exploited Vulnerabilities catalog, so there is no KEV-confirmed active exploitation and no KEV-mandated remediation deadline at this time. That status can change without notice; readers should confirm against the live catalog, linked below, before relying on it.
The only vendor reference supplied is the MSRC update guide entry. Consistent with the exclusively-hosted-service tag, no customer-installable patch or required action is specified in the available data; administrators should consult the MSRC advisory directly for current guidance.
Sources
- NVD, CVE-2026-65667: https://nvd.nist.gov/vuln/detail/CVE-2026-65667
- Microsoft MSRC Update Guide: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65667
- CISA Known Exploited Vulnerabilities Catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog