Improper Authorization in Handler for Custom URL Scheme in Microsoft Authenticator for IOS and Microsoft Authenticator for Android - CVE-2026-26123
Published: March 10, 2026
Vulnerability details
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to improper authorization in handler for custom URL scheme in Microsoft Authenticator. A remote attacker can gain access to sensitive information if the user selects a malicious application as the handler for the sign‑in deep link.
Affected software
Microsoft Authenticator for Android
How to mitigate CVE-2026-26123
Microsoft Authenticator for Android - update to 6.2511.7533