Urgent.News

What's breaking now, across thousands of outlets.

Tech

CVE-2026-80097: The Authenticator App Is a Credential Store, Not Just a Prompt

CVE-2026-80097: The Authenticator App Is a Credential Store, Not Just a Prompt Microsoft Authenticator was the control most organisations reached for once they moved past SMS codes. CVE-2026-80097 concerns improper authentication in that app, and it is worth reading carefully rather than filing under "mobile bug". What the record says NVD describes CVE-2026-80097 as improper authentication in…

Microsoft's Authenticator App is often viewed simply as a second factor for authentication, but recent research reveals it functions much more like a comprehensive credential store. The CVE-2026-80097 vulnerability exposes improper authentication within the app, allowing an unauthorized attacker to potentially elevate their privileges locally on a device.

The National Vulnerability Database (NVD) characterizes this flaw as CWE-287, which denotes improper authentication. With a CVSS base score of 8.6, this is considered a high severity issue. Published on September 8, 2026, Microsoft has since issued guidance on addressing this vulnerability. The key distinction here is that this is not a remote takeover of the vault, but rather a flaw in the authentication logic of the app itself, which users have come to rely on for various identities and accounts.

Microsoft Authenticator goes beyond merely generating one-time codes. It stores passwordless credentials, push notification registrations, and account metadata for every linked identity. On shared or supervised devices, it can manage multiple accounts, making the app's internal state a significant security control. If an attacker has already compromised a device, the question arises whether they need additional access to reach this internal state.

Elevating privileges within a credential-bearing app like Microsoft Authenticator significantly changes the answer, impacting every account the app can operate for.

To mitigate this vulnerability, organizations should enforce strong device passcodes and biometric authentication for any device housing the Authenticator app. The app's lock screen, while convenient, is merely a convenience feature; the platform's lock screen remains the primary control. Additionally, enabling number matching over simple approve/deny methods can help prevent MFA fatigue attacks, although it does not directly address this specific flaw.

Limiting the number of accounts a single device can hold can also reduce the potential blast radius of such a vulnerability.

Microsoft's own update guide provides the vendor reference for addressing this issue. However, the challenge lies in the fact that mobile applications, including the Authenticator app, often fall outside standard software inventory management. Organizations must therefore use existing device management systems to track installed app versions on managed devices and enforce updates through policy on unmanaged devices.

Outdated Authenticator builds should be treated with the same urgency as unpatched VPN clients, ensuring comprehensive security across all devices.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

Moldova Rises Eight Places in Global Startup Ranking as Funding Expands

Moldova rose eight places to 82nd in StartupBlink’s 2026 Global Startup Ecosystem Index, according to an announcement issued by Startup Moldova Foundation in Chișinău on October 5.

  • Moldova climbs to 82nd place in global startup ranking.
  • Ecosystem score increases by 91.9% from 2025 to 2026.
  • Over $17 million in funding secured by local startups in 2025.

More from Monday 5 October →