Junglewise Threat Intelligence

CVE-2026-80097: Microsoft Authenticator improper authentication privilege escalation

CVE-2026-80097 · Severity: high · CVSS 8.6 · Published 2026-09-08

Executive brief

Microsoft Authenticator is a mobile authentication app used by organizations to verify user identity and secure account access. This vulnerability allows a local attacker to bypass authentication controls and gain elevated privileges on a device, potentially compromising corporate accounts and sensitive data access.

Technical details

The vulnerability is an improper authentication flaw in Microsoft Authenticator that allows privilege escalation through local attack vector. An attacker with local access to a device can exploit insufficient authentication validation to elevate privileges. This requires local code execution or device access as a precondition. A patch has been released by Microsoft; users should update Authenticator to the latest available version immediately.

Affected products

  • Microsoft Authenticator

Timeline

  • 2026-09-08: disclosed

References

Related threats