CVE-2026-80097: Microsoft Authenticator Elevation of Privilege Vulnerability

Overview

Severity
High (CVSS 8.6)
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C
Category
Elevation of Privilege
Exploit Status
Not Exploited
Exploitation Likelihood
Less Likely
Patch Tuesday
2026-Sep
Released
2026-09-08

Description

Improper authentication in Microsoft Authenticator allows an unauthorized attacker to elevate privileges locally.

FAQ

What privileges could be gained by an attacker who successfully exploited the vulnerability? An attacker who successfully exploited this vulnerability could potentially gain the ability to authenticate against a remote host using the current user’s credentials. How could an attacker exploit this vulnerability? An attacker could exploit this vulnerability by installing and running a malicious application on an affected Android device and convincing the user to complete an authentication flow in Microsoft Authenticator. Successful exploitation could allow the attacker to obtain authentication tokens and access resources as the affected user.

Affected Products (1)

Apps

  • Microsoft Authenticator for Android

Security Updates (1)

Acknowledgments

Ofek Levin with <a href="https://enclave.ai/">Enclave</a>

Revision History

  • 2026-09-08: Information published.