CVE-2026-65680
onedrive: Improper Link Resolution Before File Access ('Link Following') (CVE-2026-65680)
mediumEPSS 0.4%
Affected
- microsoft/onedrive
lt *..26.095.0519.0003
Description
Improper link resolution before file access ('link following') in Microsoft OneDrive allows an authorized attacker to elevate privileges locally.
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
microsoftonedrive
26.095.0519.0003fixed from 26.095.0519.0003Metrics
Show all metrics
Severity
medium
66.05
no public PoC known
6.7
Published
2026-08-11 17:45 UTC
CWE-59
Weakness classes (CWE)
CWE-59Base
Improper Link Resolution Before File Access ('Link Following')
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
cwe.mitre.org →
References & sources
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- New CVE Received2026-08-11 18:18 UTC· secure@microsoft.com
- Affected: OneDrive for MacOS
- Description: Improper link resolution before file access ('link following') in Microsoft OneDrive allows an authorized attacker to elevate privileges locally.
- CVSS V3.1: AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- CWE: CWE-59