CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2026-41615

CVSS 9.6v3.1pub. 2026-05-14upd. 2026-05-15

Exposure of sensitive information to an unauthorized actor in Microsoft Authenticator allows an unauthorized attacker to disclose information over a network.

🤖 AI Analysis
How it works

The vulnerability classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) consists of improper disclosure of sensitive data by the Microsoft Authenticator application. The attacker does not need any permissions, but user interaction is required (UI:R). The network vector (AV:N) and lack of attack complexity requirements (AC:L) mean that the exploit can be conducted remotely and without advanced technical knowledge. The scope of the attack extends beyond the base component (S:C), which indicates potential impact on other system elements.

Impact

An attacker can gain access to sensitive information processed by Microsoft Authenticator, and as a result, compromise the confidentiality, integrity, and availability of the victim's resources.

Mitigation & patch

Apply patches available from the vendor in accordance with references published by Microsoft Security Response Center at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41615. It is recommended to immediately update the Microsoft Authenticator application to the latest available version.

Who is affected

Microsoft Authenticator — versions specified in vendor references (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41615)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
  • Microsoft Authenticator

    APP
    Microsoft
    < 6.8.47< 6.2605.2973
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2024-21390HIGH7.1same product

Microsoft Authenticator Elevation of Privilege Vulnerability

CVE-2026-26123MEDIUM5.5same product

Brak CWE w kategorii RCA w Microsoft Authenticator pozwala nieuprawnionym atakującym na ujawnienie informacji ...

CVE-2026-55040CRITICAL9.1⚠ KEVPL ✓same vendor

Obejście uwierzytelnienia w Microsoft SharePoint Server (RCE-ready)

CVE-2026-50522CRITICAL9.8⚠ KEVPL ✓same vendor

RCE przez deserializację niezaufanych danych w Microsoft SharePoint

CVE-2026-58644CRITICAL9.8⚠ KEVPL ✓same vendor

Zdalne wykonanie kodu poprzez deserializację w Microsoft SharePoint Server