Sceawere
Vulnerability Detail
CVE-2026-65767UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Microsoft Teams Android XSS Spoofing
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.8
- Creation Date
- 7h ago
- Vendor
- Microsoft
- Product
- Microsoft Teams for Android
- Attack Type
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Teams for Android allows an authorized attacker to perform spoofing over a network.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.8",
"pubDate": "2026-08-11T17:18:55.997Z",
"pubdate": "2026-08-11T17:18:55.997Z",
"executiveSummary": "A cross-site scripting vulnerability exists within Microsoft Teams for Android, specifically stemming from the improper neutralization of input during web page generation. This security flaw enables an authorized attacker to execute unauthorized scripts and perform spoofing attacks over a network.\nThe primary impact of this vulnerability is the potential manipulation of the application's user interface or data presentation via spoofing, which can undermine the integrity and confidentiality of user interactions within the platform. The affected system is Microsoft Teams for Android.\nRisk implications include the potential for attackers to deceive users by injecting malicious content into rendered web pages or message contexts, leading to unauthorized actions or exposure of sensitive interface elements. To execute this attack, the adversary must be authorized and capable of transmitting crafted input over the network to the targeted application instance.\nExploitation relies on the application failing to properly sanitize or neutralize user-supplied input before rendering it within the web page context of the mobile client. While specific authentication prerequisites are tied to an authorized attacker profile, the capability to reach the vulnerable component over a network vector is a fundamental requirement for successful exploitation.",
"technicalDetails": "The root cause of the vulnerability is the improper neutralization of input during web page generation within Microsoft Teams for Android. This failure in input sanitization allows malicious data supplied by an attacker to be interpreted and executed as active content or markup within the application's embedded web rendering components.\nThe vulnerable component handles the parsing and display of dynamic content or messages within Microsoft Teams for Android. Because the application fails to adequately encode or sanitize incoming data, injected payloads are processed directly by the rendering engine.\nThe attack flow begins when an authorized attacker crafts a malicious payload designed to exploit the cross-site scripting weakness. The attacker then transmits this payload over a network to the targeted Microsoft Teams for Android client, typically via messaging channels or other data ingestion vectors supported by the application.\nUpon receipt, the vulnerable component processes the input without proper neutralization. When the application generates the internal web page or view containing the unmitigated input, the injected payload is triggered within the execution context of the mobile client.\nThe post-exploitation impact includes the execution of arbitrary script logic in the context of the affected application interface, facilitating spoofing attacks. An attacker can manipulate the visual presentation of data, potentially misleading the user regarding the authenticity of messages or interface elements, thereby compromising the trustworthiness of the communication channel.\nPrerequisites for exploitation include network connectivity to deliver the payload and an authorized attacker status within the targeted environment. The vulnerability is explootable remotely over a network against the specified mobile application platform without requiring physical access to the device."
}