🟡 Medium  |  Source: Microsoft Security Response Center


CVE-2026-58650 is a security feature bypass vulnerability in Visual Studio Code that allows an attacker to circumvent authorisation controls through a user-controlled key. Exploitation requires local access, meaning an attacker would need to already have a foothold on the target machine. Whilst the local requirement limits the blast radius, VS Code’s widespread use in developer and cloud engineering workflows makes this a meaningful risk in environments where workstations access sensitive cloud resources.

Security Architect’s Take: Ensure VS Code is updated to the patched version across all developer and engineer endpoints, particularly workstations with access to cloud consoles, infrastructure-as-code pipelines, or stored credentials — a bypassed security control on such machines could enable lateral movement into cloud environments.

Original advisory: CVE-2026-58650 Visual Studio Code Security Feature Bypass Vulnerability