Improper authorization in Microsoft Teams allows an authorized attacker to disclose information over a network.
The vulnerability consists of improper authorization verification in the Microsoft Teams application — the system does not correctly check whether the logged-in user has the right to access specific resources or data. An attacker with an account in the environment (authorized user) can send an appropriately crafted network request, bypassing access controls and gaining access to information to which they should not have permissions. The attack vector is network-based, does not require high privileges or victim interaction, which significantly lowers the entry threshold for a potential attacker.
An attacker can disclose sensitive information stored or processed in Microsoft Teams, including potentially messages, files, organizational data, or other resources available on the platform. The changed scope (Scope: Changed) suggests that the impact may affect components or data beyond the direct context of the attacker's session.
Apply patches available from the vendor in accordance with references published at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33823. For Microsoft Teams, updates are most commonly distributed automatically — administrators should verify that all instances of the application (desktop and web) are updated to the latest version.
Microsoft Teams — specific product versions indicated in the vendor references (Microsoft Security Response Center).
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:NMicrosoft Teams
APPMicrosoftall versions
Related vulnerabilities
Nieprawidłowe uwierzytelnianie w Microsoft Teams umożliwia privilege escalation
Brak autoryzacji w Microsoft Teams umożliwia privilege escalation
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote at...
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Teams for An...
Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams for Android ...