Junglewise Threat Intelligence

CVE-2026-65680: Microsoft OneDrive symlink following privilege escalation

CVE-2026-65680 · Severity: medium · CVSS 6.7 · Published 2026-08-11

Vendors: Microsoft.

Executive brief

Microsoft OneDrive is a file synchronization and cloud storage service used by millions of organizations and individuals. A local privilege escalation vulnerability exists where an authorized user can exploit improper link resolution to access files or escalate permissions beyond their intended level, potentially compromising account security or sensitive data.

Technical details

The vulnerability is a symlink following (link resolution) issue in Microsoft OneDrive that allows an authorized local attacker to elevate privileges. The vulnerability exists in how OneDrive resolves symbolic links before accessing files; an attacker with local access can create or manipulate symbolic links to cause OneDrive to access files or resources outside the intended scope. This requires prior authentication and local system access. An attacker can use this to read, modify, or delete files with OneDrive's elevated permissions, potentially escalating to system-level privileges depending on the OneDrive process context.

Affected products

  • Microsoft OneDrive

Timeline

  • 2026-08-11: disclosed

References