Jun 2026: Visual Studio Code Elevation of Privilege Vulnerability
CVE-2026-40376 Published on June 9, 2026

Visual Studio Code Elevation of Privilege Vulnerability
Improper input validation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.

Vendor Advisory NVD

Weakness Type

Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.


Products Associated with CVE-2026-40376

Want to know whenever a new CVE is published for Microsoft Visual Studio Code? stack.watch will email you.

 

Affected Versions

Microsoft Visual Studio Code: