CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2026-47281

CVSS 9.6v3.1pub. 2026-06-09upd. 2026-07-09

Missing authorization in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.

🤖 AI Analysis
How it works

The vulnerability results from improper input data validation (CWE-306, CWE-798, CWE-862) in the Visual Studio Code application. A remote, unauthenticated attacker can supply specially crafted input data that leads to unauthorized privilege escalation. The network attack vector combined with lack of authentication requirements means the attack can be carried out without prior access to the victim's system, although it requires user interaction.

Impact

An attacker can obtain elevated privileges on the victim's system, potentially leading to complete compromise of confidentiality, integrity, and availability of resources — including user data and development environment.

Mitigation & patch

Patches available from the vendor should be applied according to the references. Detailed information about patches is available at: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47281

Who is affected

Versions indicated in the vendor's references (Microsoft Visual Studio Code)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
  • Microsoft Visual Studio Code

    APP
    Microsoft
    1.0.0 – 1.123.1 (excl.)
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2026-59113HIGH8.8same product

Missing authorization in Visual Studio Code allows an unauthorized attacker to execute code over a network.

CVE-2026-65675HIGH7.1same product

No cwe for this issue in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to bypass a...

CVE-2026-58650HIGH7.8same product

Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypa...

CVE-2026-54981HIGH7.8same product

Inclusion of functionality from untrusted control sphere in Visual Studio Code - Python extension allows an un...

CVE-2026-69278HIGH7.8same product

Incorrect authorization in Visual Studio Code allows an unauthorized attacker to bypass a security feature loc...