Incorrect authorization in Visual Studio Code - CVE-2026-69278

 

Incorrect authorization in Visual Studio Code - CVE-2026-69278

Published: August 12, 2026


Vulnerability identifier: #VU141836
CSH Severity: High
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-69278
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass a security feature.

The vulnerability exists due to incorrect authorization in the Workspace Trust feature when opening an untrusted workspace. A remote attacker can trick the victim into opening an untrusted workspace to bypass a security feature.

Successful exploitation can allow content from an untrusted workspace to run commands or code without the user first granting trust.


Affected software

Visual Studio Code

How to mitigate CVE-2026-69278

Install security update from vendor's website.

Visual Studio Code - update to 1.132.1

External References

Related Security Bulletins