CVE-2026-65768
8.8Microsoft · Microsoft Teams for Android
A path traversal vulnerability in Microsoft Teams for Android allows an unauthenticated, remote attacker to execute arbitrary code.
Executive summary
Microsoft Teams for Android is susceptible to a path traversal vulnerability that could allow a remote attacker to execute arbitrary code on the affected device.
Vulnerability
This vulnerability, categorized as CWE-22, stems from improper limitation of a pathname to a restricted directory. The CVSS vector indicates that this can be exploited remotely by an unauthenticated attacker, although it requires user interaction (UI:R).
Business impact
With a CVSS score of 8.8, this vulnerability represents a critical threat to mobile security. Successful exploitation could lead to full system compromise, allowing an attacker to access sensitive data, install malicious payloads, or disrupt the confidentiality and availability of the application.
Remediation
Immediate Action: Update Microsoft Teams for Android to version 1.0.0.2026133602 or later immediately.
Proactive Monitoring: Review mobile security logs for suspicious file system access or unexpected application behavior following updates.
Compensating Controls: Implement robust mobile security endpoint detection and response (EDR) solutions to identify and block unauthorized code execution attempts.
Exploitation status
Public Exploit Available: No
Analyst recommendation
The risk of remote code execution makes this an urgent security concern for all organizations using Microsoft Teams on Android. Administrators must ensure that all enterprise-managed devices receive the update to eliminate this vulnerability.