CVE-2026-80097: Microsoft Authenticator Elevation of Privilege Vulnerability
Improper authentication in Microsoft Authenticator allows an unauthorized attacker to elevate privileges locally.
Other sources
Microsoft Authenticator Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.3.0
Event History
Frequently Asked Questions
What access and interaction are required to exploit this issue?
The attacker must have local access to the affected device. No privileges are required beforehand, but exploitation requires user interaction.
What is the potential impact if exploitation succeeds?
A successful attack can allow an unauthorized attacker to elevate privileges locally. The supplied severity vector indicates potential high impact to confidentiality, integrity, and availability, with scope changed.
Which product is identified as affected?
The affected software listed is Microsoft Authenticator for Android from Microsoft.