Exposure of sensitive information to an unauthorized actor in Microsoft Authenticator allows an unauthorized attacker to disclose information over a network.
The vulnerability classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) consists of improper disclosure of sensitive data by the Microsoft Authenticator application. The attacker does not need any permissions, but user interaction is required (UI:R). The network vector (AV:N) and lack of attack complexity requirements (AC:L) mean that the exploit can be conducted remotely and without advanced technical knowledge. The scope of the attack extends beyond the base component (S:C), which indicates potential impact on other system elements.
An attacker can gain access to sensitive information processed by Microsoft Authenticator, and as a result, compromise the confidentiality, integrity, and availability of the victim's resources.
Apply patches available from the vendor in accordance with references published by Microsoft Security Response Center at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41615. It is recommended to immediately update the Microsoft Authenticator application to the latest available version.
Microsoft Authenticator — versions specified in vendor references (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41615)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:HMicrosoft Authenticator
APPMicrosoft< 6.8.47< 6.2605.2973
Related vulnerabilities
Microsoft Authenticator Elevation of Privilege Vulnerability
Brak CWE w kategorii RCA w Microsoft Authenticator pozwala nieuprawnionym atakującym na ujawnienie informacji ...
Obejście uwierzytelnienia w Microsoft SharePoint Server (RCE-ready)
RCE przez deserializację niezaufanych danych w Microsoft SharePoint
Zdalne wykonanie kodu poprzez deserializację w Microsoft SharePoint Server