Missing authorization in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.
The vulnerability results from improper input data validation (CWE-306, CWE-798, CWE-862) in the Visual Studio Code application. A remote, unauthenticated attacker can supply specially crafted input data that leads to unauthorized privilege escalation. The network attack vector combined with lack of authentication requirements means the attack can be carried out without prior access to the victim's system, although it requires user interaction.
An attacker can obtain elevated privileges on the victim's system, potentially leading to complete compromise of confidentiality, integrity, and availability of resources — including user data and development environment.
Patches available from the vendor should be applied according to the references. Detailed information about patches is available at: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47281
Versions indicated in the vendor's references (Microsoft Visual Studio Code)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:HMicrosoft Visual Studio Code
APPMicrosoft1.0.0 – 1.123.1 (excl.)
Related vulnerabilities
Missing authorization in Visual Studio Code allows an unauthorized attacker to execute code over a network.
No cwe for this issue in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to bypass a...
Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypa...
Inclusion of functionality from untrusted control sphere in Visual Studio Code - Python extension allows an un...
Incorrect authorization in Visual Studio Code allows an unauthorized attacker to bypass a security feature loc...