CVE-2026-81378: Visual Studio Code Security Feature Bypass Vulnerability
Published Sep 8, 2026
·Updated
Interpretation conflict in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
Other sources
Visual Studio Code Security Feature Bypass Vulnerability
— Microsoft
Affected Software
1 affected componentFixes available
Microsoft Visual Studio Code<1.136.2
1.136.2
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.136.2
Event History
Sep 8, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·02:00 PM
Description
CVE Published
via MITRE·05:13 PM
Data Sourced
via MITRE·05:13 PM
DescriptionSeverity
Frequently Asked Questions
1
What attacker interaction is required for exploitation?
The attacker can attempt exploitation over a network without prior privileges, but user interaction is required.
2
What security impact is indicated?
Successful exploitation can bypass a security feature and has high confidentiality impact and low integrity impact. No availability impact is indicated.
3
Is the affected configuration or fixed version known from the available information?
No affected version range, default-configuration status, or remediation version is provided in the available information.