CVE-2026-65680 PUBLISHED

Microsoft OneDrive for MacOS Elevation of Privilege Vulnerability

Assigner: microsoft
Reserved: 22.07.2026 Published: 11.08.2026 Updated: 12.08.2026

Improper link resolution before file access ('link following') in Microsoft OneDrive allows an authorized attacker to elevate privileges locally.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
CVSS Score: 6.7

Product Status

Vendor Microsoft
Product OneDrive for MacOS
Versions
  • affected from 26.0.0.0 to 26.095.0519.0003 (excl.)

References

Problem Types