Junglewise Threat Intelligence

CVE-2026-78462: Microsoft Visual Studio Code authorization bypass in user-controlled key

CVE-2026-78462 · Severity: high · CVSS 8.8 · Published 2026-09-08

Executive brief

Visual Studio Code is a widely-used code editor that developers rely on for secure development. This vulnerability allows an attacker to bypass authorization controls over the network by manipulating user-controlled cryptographic keys, potentially granting unauthorized access to protected features or data without proper authentication.

Technical details

This is an authorization bypass vulnerability in Visual Studio Code caused by insufficient validation of user-controlled cryptographic keys. An unauthenticated attacker can send a specially crafted network request with a manipulated key to bypass the authorization mechanism and access security-controlled features. The vulnerability requires network access to the affected instance and does not require user interaction. A successful exploit could allow an attacker to circumvent security controls and gain unauthorized access to protected functionality.

Affected products

  • Microsoft Visual Studio Code <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats