Junglewise Threat Intelligence

CVE-2026-42835: Microsoft Teams for Android injection vulnerability

CVE-2026-42835 · Severity: high · CVSS 8.1 · Published 2026-06-09

Technologies: Microsoft Teams for Android. Vendors: Microsoft.

Executive brief

Microsoft Teams for Android is a mobile communication application used for business collaboration and messaging. A security vulnerability in this app allows a logged-in user to improperly inject data that could lead to the unauthorized disclosure of sensitive information. This could result in a breach of internal communications or corporate data privacy.

Technical details

An injection vulnerability (CWE-74) exists in Microsoft Teams for Android due to the improper neutralization of special elements in output used by a downstream component. An authenticated attacker with low privileges can exploit this flaw over the network without any user interaction. Successful exploitation allows the attacker to disclose sensitive information and potentially impact service availability, as indicated by the CVSS vector. The vulnerability was disclosed by Microsoft, and users are advised to update their Android application to the latest version available in the Google Play Store.

Affected products

  • Microsoft Teams for Android

Timeline

  • 2026-06-09: disclosed: Initial disclosure by Microsoft and NVD publication.
  • 2026-06-09: advisory

References

Related threats