Sceawere

Vulnerability Detail

CVE-2026-65767UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Microsoft Teams Android XSS Spoofing

Vulnerability Metadata

Severity
High
Score / CVSS
8.8
Creation Date
7h ago
Vendor
Microsoft
Product
Microsoft Teams for Android
Attack Type
CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Teams for Android allows an authorized attacker to perform spoofing over a network.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.8",
  "pubDate": "2026-08-11T17:18:55.997Z",
  "pubdate": "2026-08-11T17:18:55.997Z",
  "executiveSummary": "A cross-site scripting vulnerability exists within Microsoft Teams for Android, specifically stemming from the improper neutralization of input during web page generation. This security flaw enables an authorized attacker to execute unauthorized scripts and perform spoofing attacks over a network.\nThe primary impact of this vulnerability is the potential manipulation of the application's user interface or data presentation via spoofing, which can undermine the integrity and confidentiality of user interactions within the platform. The affected system is Microsoft Teams for Android.\nRisk implications include the potential for attackers to deceive users by injecting malicious content into rendered web pages or message contexts, leading to unauthorized actions or exposure of sensitive interface elements. To execute this attack, the adversary must be authorized and capable of transmitting crafted input over the network to the targeted application instance.\nExploitation relies on the application failing to properly sanitize or neutralize user-supplied input before rendering it within the web page context of the mobile client. While specific authentication prerequisites are tied to an authorized attacker profile, the capability to reach the vulnerable component over a network vector is a fundamental requirement for successful exploitation.",
  "technicalDetails": "The root cause of the vulnerability is the improper neutralization of input during web page generation within Microsoft Teams for Android. This failure in input sanitization allows malicious data supplied by an attacker to be interpreted and executed as active content or markup within the application's embedded web rendering components.\nThe vulnerable component handles the parsing and display of dynamic content or messages within Microsoft Teams for Android. Because the application fails to adequately encode or sanitize incoming data, injected payloads are processed directly by the rendering engine.\nThe attack flow begins when an authorized attacker crafts a malicious payload designed to exploit the cross-site scripting weakness. The attacker then transmits this payload over a network to the targeted Microsoft Teams for Android client, typically via messaging channels or other data ingestion vectors supported by the application.\nUpon receipt, the vulnerable component processes the input without proper neutralization. When the application generates the internal web page or view containing the unmitigated input, the injected payload is triggered within the execution context of the mobile client.\nThe post-exploitation impact includes the execution of arbitrary script logic in the context of the affected application interface, facilitating spoofing attacks. An attacker can manipulate the visual presentation of data, potentially misleading the user regarding the authenticity of messages or interface elements, thereby compromising the trustworthiness of the communication channel.\nPrerequisites for exploitation include network connectivity to deliver the payload and an authorized attacker status within the targeted environment. The vulnerability is explootable remotely over a network against the specified mobile application platform without requiring physical access to the device."
}
CVE-2026-65767: Microsoft Teams Android XSS Spoofing (HIGH Severity, CVSS: 8.8) - Sceawere