CVE-2026-81376: Visual Studio Code Security Feature Bypass Vulnerability
Incomplete comparison with missing factors in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
Other sources
Visual Studio Code Security Feature Bypass Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.136.2
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The vulnerability is reachable over a network and requires no prior privileges. User interaction is required for exploitation.
What impact could successful exploitation have?
Successful exploitation can bypass a security feature and is rated as having high confidentiality, integrity, and availability impact. The score also indicates the impact can extend beyond the initially affected security authority.
Is exploit code or active exploitation known?
The supplied data marks exploit maturity as unproven; it does not indicate that public exploit code or active exploitation is known.