AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-65680

MEDIUM · CVSS 6.7 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-08-11 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

Microsoft OneDrive is vulnerable due to improper link resolution before file access, enabling an authorized attacker to elevate their privileges locally. This could lead to unauthorized access to sensitive files or system functions. Organizations using OneDrive should prioritize addressing this vulnerability to mitigate potential risks associated with privilege escalation.

CVE
CVE-2026-65680
Severity
MEDIUM
CVSS
6.7
EPSS
0.29%
Microsoft

Original NVD Description

Improper link resolution before file access ('link following') in Microsoft OneDrive allows an authorized attacker to elevate privileges locally.