CVE-2026-78462
massAuthorization bypass via user-controlled key in Microsoft Visual Studio Code
Microsoft Visual Studio Code contains an authorization bypass flaw (CWE-639) in which authorization decisions depend on a user-controlled key, allowing an unauthorized attacker to supply or alter that key so a security feature check is bypassed. The flaw is exploitable over a network with no privileges required, but the CVSS vector indicates user interaction is required to trigger it. A successful attacker gains bypass of the affected security feature, with high impact to confidentiality, integrity, and availability per the CVSS assessment. Anyone running an affected Visual Studio Code installation is potentially exposed, although the available data does not specify the affected version ranges. Exploitation has not been observed: there is no known public proof-of-concept, the flaw is not in CISA's KEV, and EPSS estimates only a 0.5% probability of exploitation in the next 30 days.
What to do: Monitor Microsoft's MSRC advisory for CVE-2026-78462 for the confirmed affected and fixed version ranges, and deploy the patched Visual Studio Code release as soon as it is published (VS Code auto-update typically delivers security fixes). Until patched, exercise caution with untrusted files, links, and prompts in VS Code, since exploitation requires user interaction. With EPSS at 0.5%, no public PoC, and no KEV listing, normal patch-cycle prioritization is reasonable, but verify the fix across developer workstations and build environments where VS Code is installed.
| Microsoft Visual Studio Code | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
- Vendors
- microsoft
- Products
- visual studio code
- Weakness
- CWE-639
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.