PatchSiren cyber security CVE debrief
CVE-2026-65680 Microsoft CVE debrief
Microsoft OneDrive for MacOS Elevation of Privilege Vulnerability allows an authorized attacker to elevate privileges locally due to improper link resolution before file access. The vulnerability has a CVSS score of 6.7 and is classified as MEDIUM severity. Microsoft has released an advisory and patch for this vulnerability. Defenders should assess exposure and prioritize patching. The affected version is OneDrive for MacOS 26.0.0.0, with versions less than 26.095.0519.0003 being vulnerable.
- Vendor
- Microsoft
- Product
- OneDrive for MacOS
- CVSS
- MEDIUM 6.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-11
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-08-11
- Advisory updated
- 2026-10-08
Who should care
Defenders responsible for Microsoft OneDrive for MacOS deployments should assess exposure and prioritize patching, as an authorized attacker could exploit this vulnerability to elevate privileges locally.
Why it matters
CVE-2026-65680 is a MEDIUM-severity elevation of privilege vulnerability in Microsoft OneDrive for MacOS. Defenders should prioritize verifying and applying the available patch, as well as monitoring for potential exploitation attempts. The vulnerability allows an authorized attacker to elevate privileges locally due to improper link resolution before file access.
- Verify and apply the available patch from Microsoft to prevent potential exploitation
- Monitor for potential exploitation attempts to detect possible attacks
- Review and update affected versions to ensure the vulnerability is addressed
Technical summary
The vulnerability is caused by improper link resolution before file access in Microsoft OneDrive for MacOS, allowing an authorized attacker to elevate privileges locally. The affected version is OneDrive for MacOS 26.0.0.0, with versions less than 26.095.0519.0003 being vulnerable.
Defensive priority
Defenders should prioritize verifying and applying the available patch from Microsoft, as well as monitoring for potential exploitation attempts.
Recommended defensive actions
- Verify and apply the available patch from Microsoft
- Monitor for potential exploitation attempts
- Review and update affected versions
Evidence notes
The CVE record and Microsoft advisory provide details on the vulnerability, including its CVSS score and affected versions. The vulnerability allows an authorized attacker to elevate privileges locally due to improper link resolution before file access. The affected version is OneDrive for MacOS 26.0.0.0, with versions less than 26.095.0519.0003 being vulnerable. Defenders should verify and apply the available patch from Microsoft, as well as monitor for potential exploitation attempts
Sources and references
Verified primary and authoritative sources
-
CVE-2026-65680 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-65680
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-65680 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-65680
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Microsoft OneDrive for MacOS Elevation of Privilege Vulnerability
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/65xxx/CVE-2026-65680.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65680
Supplemental source - vendor-advisory, patch
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.