Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
5.5

Microsoft Authenticator: Unauthorized Local Information Disclosure

CVE-2026-26123
Summary

The Microsoft Authenticator app may leak sensitive information to unauthorized users if accessed locally. This can happen when an attacker gains physical access to a device running the app. To protect against this, ensure that your device is secured with strong passwords and up-to-date security settings.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versionsFix available
microsoft authenticator <= 6.8.40
microsoft authenticator <= 6.2511.7533
Original title
Cwe is not in rca categories in Microsoft Authenticator allows an unauthorized attacker to disclose information locally.
Original description
Cwe is not in rca categories in Microsoft Authenticator allows an unauthorized attacker to disclose information locally.
nvd CVSS3.1 5.5
Vulnerability type
CWE-939
Published: 10 Mar 2026 · Updated: 14 Mar 2026 · First seen: 10 Mar 2026