VDB
GCVE-110-NCSC-2026-286
GCVE-110-NCSC-2026-286
Advisory PublishedCVSS 9.6/10
A path traversal vulnerability in Microsoft Teams for Android allows unauthorized attackers to execute code remotely by improperly restricting pathname access to a restricted directory.
Weaknesses (CWE)
CWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')CWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')CWE-23Relative Path TraversalCWE-502Deserialization of Untrusted DataCWE-863Incorrect AuthorizationCWE-94Improper Control of Generation of Code ('Code Injection')CWE-918Server-Side Request Forgery (SSRF)CWE-306Missing Authentication for Critical FunctionCWE-88Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')CWE-522Insufficiently Protected CredentialsCWE-347Improper Verification of Cryptographic SignatureCWE-862Missing AuthorizationCWE-923Improper Restriction of Communication Channel to Intended EndpointsCWE-122Heap-based Buffer OverflowCWE-125Out-of-bounds ReadCWE-416Use After FreeCWE-77Improper Neutralization of Special Elements used in a Command ('Command Injection')CWE-843Access of Resource Using Incompatible Type ('Type Confusion')CWE-121Stack-based Buffer OverflowCWE-787Out-of-bounds WriteCWE-459Incomplete CleanupCWE-822Untrusted Pointer DereferenceCWE-908Use of Uninitialized ResourceCWE-190Integer Overflow or WraparoundCWE-197Numeric Truncation ErrorCWE-126Buffer Over-readCWE-295Improper Certificate ValidationCWE-59Improper Link Resolution Before File Access ('Link Following')
Risk Scores
CVSS 3.1
9.6/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Microsoft | vers:unknown/* | — | — |
Aliases
CVE-2026-50515CVE-2026-57105CVE-2026-58639CVE-2026-58651CVE-2026-62827CVE-2026-62829CVE-2026-62836CVE-2026-62837CVE-2026-62839CVE-2026-62842CVE-2026-62882CVE-2026-62896CVE-2026-62917CVE-2026-62918CVE-2026-63512CVE-2026-63513CVE-2026-63514CVE-2026-63515CVE-2026-63516CVE-2026-63517CVE-2026-63518CVE-2026-63519CVE-2026-63520CVE-2026-63521CVE-2026-63524CVE-2026-63525CVE-2026-63526CVE-2026-63527CVE-2026-63528CVE-2026-63529CVE-2026-63530CVE-2026-63531CVE-2026-63532CVE-2026-63533CVE-2026-64897CVE-2026-64898CVE-2026-64899CVE-2026-64900CVE-2026-64901CVE-2026-64902CVE-2026-64903CVE-2026-64904CVE-2026-64905CVE-2026-64906CVE-2026-64907CVE-2026-64908CVE-2026-64909CVE-2026-64910CVE-2026-64911CVE-2026-64912CVE-2026-64914CVE-2026-64915CVE-2026-64916CVE-2026-64917CVE-2026-64919CVE-2026-64920CVE-2026-64921CVE-2026-64922CVE-2026-65656CVE-2026-65657CVE-2026-65658CVE-2026-65660CVE-2026-65661CVE-2026-65663CVE-2026-65664CVE-2026-65665CVE-2026-65667CVE-2026-65680CVE-2026-65767CVE-2026-65768CVE-2026-65769CVE-2026-65807CVE-2026-66805CVE-2026-66806CVE-2026-66807CVE-2026-66808CVE-2026-66809CVE-2026-66810CVE-2026-68792CVE-2026-68793CVE-2026-68794CVE-2026-68795CVE-2026-68796CVE-2026-68797CVE-2026-68798CVE-2026-68799CVE-2026-68800CVE-2026-68801CVE-2026-68802CVE-2026-68803CVE-2026-68804CVE-2026-68805CVE-2026-68806CVE-2026-68807CVE-2026-68808CVE-2026-68809CVE-2026-68810CVE-2026-68811CVE-2026-68812CVE-2026-68813CVE-2026-68814CVE-2026-68815CVE-2026-68816CVE-2026-68817CVE-2026-70130CVE-2026-70306CVE-2026-70310CVE-2026-70311CVE-2026-70312CVE-2026-70313CVE-2026-70314CVE-2026-70315CVE-2026-70316CVE-2026-70317CVE-2026-70318CVE-2026-70319CVE-2026-70320CVE-2026-70321CVE-2026-70322CVE-2026-70323CVE-2026-70324CVE-2026-70325CVE-2026-70326CVE-2026-70327CVE-2026-70328CVE-2026-70329CVE-2026-70332CVE-2026-70355
References
Browse GCVE Records
3,530 records in the GCVE database · Updated September 5, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.