ZeroHour

CVE-2026-78462

mass

Authorization bypass via user-controlled key in Microsoft Visual Studio Code

CVSS 3.1
8.8 high
EPSS
<1%p42
Published
()
Modified
AI analysis

Microsoft Visual Studio Code contains an authorization bypass flaw (CWE-639) in which authorization decisions depend on a user-controlled key, allowing an unauthorized attacker to supply or alter that key so a security feature check is bypassed. The flaw is exploitable over a network with no privileges required, but the CVSS vector indicates user interaction is required to trigger it. A successful attacker gains bypass of the affected security feature, with high impact to confidentiality, integrity, and availability per the CVSS assessment. Anyone running an affected Visual Studio Code installation is potentially exposed, although the available data does not specify the affected version ranges. Exploitation has not been observed: there is no known public proof-of-concept, the flaw is not in CISA's KEV, and EPSS estimates only a 0.5% probability of exploitation in the next 30 days.

What to do: Monitor Microsoft's MSRC advisory for CVE-2026-78462 for the confirmed affected and fixed version ranges, and deploy the patched Visual Studio Code release as soon as it is published (VS Code auto-update typically delivers security fixes). Until patched, exercise caution with untrusted files, links, and prompts in VS Code, since exploitation requires user interaction. With EPSS at 0.5%, no public PoC, and no KEV listing, normal patch-cycle prioritization is reasonable, but verify the fix across developer workstations and build environments where VS Code is installed.

Affected
Microsoft Visual Studio Code
Estimated exposure
masstens of millions of installations (VS Code holds majority developer market share) — Public developer surveys and Microsoft statements place Visual Studio Code's user base in the tens of millions, so the plausibly affected installed base exceeds 1 million machines, though only users who interact with attacker-influenced…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.

Vendors
microsoft
Products
visual studio code
Weakness
CWE-639
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.