CVE-2026-78462: Visual Studio Code Security Feature Bypass Vulnerability
Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
Other sources
Visual Studio Code Security Feature Bypass Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.136.2
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attack vector is network-based, requires no privileges, and has low attack complexity. User interaction is required for exploitation.
What is the potential impact if exploitation succeeds?
Successful exploitation can affect confidentiality, integrity, and availability at a high level. The vulnerability enables bypass of a security feature through a user-controlled key.
Is exploitation known to be occurring?
The provided exploit maturity rating is E:U, indicating that exploit code or active exploitation is not established by the available data.