CVE-2026-69306: Visual Studio Code Security Feature Bypass Vulnerability
Overview
- Severity
- High (CVSS 8.2)
- CVSS Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N/E:U/RL:O/RC:C
- Category
- Security Feature Bypass
- Exploit Status
- Not Exploited
- Exploitation Likelihood
- Less Likely
- Patch Tuesday
- 2026-Aug
- Released
- 2026-08-11
- Last Updated
- 2026-09-02
- EPSS Score
- 0.54% (percentile: 43.2%)
Description
Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
FAQ
What security feature could be bypassed by successfully exploiting this vulnerability?
An attacker who successfully exploited this vulnerability could bypass the network access restrictions enforced for the Visual Studio Code agent, allowing outbound connections to resources that the configured policy is intended to block.
Affected Products (1)
Developer Tools
Security Updates (1)
Acknowledgments
<a href="https://puh4ck3rx.github.io/">PuH4ck3rX</a> with W&M
Revision History
- 2026-08-11: Information published.
- 2026-09-02: Affected software updated with new package information.