CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2026-33823

CVSS 9.6v3.1pub. 2026-05-07upd. 2026-05-08

Improper authorization in Microsoft Teams allows an authorized attacker to disclose information over a network.

🤖 AI Analysis
How it works

The vulnerability consists of improper authorization verification in the Microsoft Teams application — the system does not correctly check whether the logged-in user has the right to access specific resources or data. An attacker with an account in the environment (authorized user) can send an appropriately crafted network request, bypassing access controls and gaining access to information to which they should not have permissions. The attack vector is network-based, does not require high privileges or victim interaction, which significantly lowers the entry threshold for a potential attacker.

Impact

An attacker can disclose sensitive information stored or processed in Microsoft Teams, including potentially messages, files, organizational data, or other resources available on the platform. The changed scope (Scope: Changed) suggests that the impact may affect components or data beyond the direct context of the attacker's session.

Mitigation & patch

Apply patches available from the vendor in accordance with references published at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33823. For Microsoft Teams, updates are most commonly distributed automatically — administrators should verify that all instances of the application (desktop and web) are updated to the latest version.

Who is affected

Microsoft Teams — specific product versions indicated in the vendor references (Microsoft Security Response Center).

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
  • Microsoft Teams

    APP
    Microsoft
    all versions
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2026-62896CRITICAL9.6PL ✓same product

Nieprawidłowe uwierzytelnianie w Microsoft Teams umożliwia privilege escalation

CVE-2026-65667CRITICAL10.0PL ✓same product

Brak autoryzacji w Microsoft Teams umożliwia privilege escalation

CVE-2023-4863HIGH8.8⚠ KEVsame product

Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote at...

CVE-2026-65767HIGH8.8same product

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Teams for An...

CVE-2026-65768HIGH8.8same product

Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams for Android ...