Executive brief
Microsoft Authenticator, a widely used mobile application for multi-factor authentication and secure logins, contains a critical vulnerability that could allow an unauthorized person to access sensitive information. An attacker could exploit this over a network to potentially compromise user accounts or gain access to private data. This poses a significant risk to organizational security as it targets the very tool used to verify user identities.
Technical details
A vulnerability classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) exists in Microsoft Authenticator. The flaw allows a remote, unauthenticated attacker to disclose sensitive information over a network. According to the CVSS vector, the attack requires user interaction (UI:R) but has a high impact on confidentiality, integrity, and availability (C:H/I:H/A:H) with a changed scope (S:C). This suggests that an exploit could potentially lead to broader system compromise beyond the application itself. Users are advised to refer to the Microsoft Security Response Center for specific patching or mitigation guidance.
Affected products
- Microsoft Authenticator
Timeline
- 2026-05-14: disclosed
- 2026-05-14: advisory: NVD and MSRC advisory published