QSearchQSearch

CVE-2026-47281

9.6 CRITICAL

Improper input validation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network

Published: 2026-06-09 · Last updated: 2026-06-09

Severity and scoring

CVSS
9.6 CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
CWE
CWE-306, CWE-798, CWE-862

Description

Improper input validation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.

Source: NVD

References

Related CVEs

Same CWE

  • CVE-2026-26237 A missing authorization vulnerability has been reported to affect QuMagie
  • CVE-2026-46518 OpenEMR is a free and open source electronic health records and medical practice management application (7.7 HIGH)
  • CVE-2026-50512 Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privilege... (7.8 HIGH)
  • CVE-2026-9212 Insufficient authentication and input validation in the listed NETGEAR models allow users connected to the local network to execute comma...
  • CVE-2026-50507 Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack (6.8 MEDIUM)