CVE-2026-65680: Microsoft OneDrive for MacOS Elevation of Privilege Vulnerability
Improper link resolution before file access ('link following') in Microsoft OneDrive allows an authorized attacker to elevate privileges locally.
Other sources
Microsoft OneDrive for MacOS Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 26.095.0519.0003
Event History
Frequently Asked Questions
What is the severity of CVE-2026-65680?
CVE-2026-65680 has a severity rating of medium (6.7).
How do I fix CVE-2026-65680?
To fix CVE-2026-65680, ensure that you update Microsoft OneDrive for MacOS to the latest version provided by Microsoft.
What impact does CVE-2026-65680 have on my system?
CVE-2026-65680 allows an authorized attacker to elevate privileges on a system running Microsoft OneDrive for MacOS.
Is CVE-2026-65680 exploitable remotely?
CVE-2026-65680 is not exploitable remotely; the attacker must have local access to the system.
What software is affected by CVE-2026-65680?
CVE-2026-65680 affects Microsoft OneDrive for MacOS.