CVE-2026-47282
Analyzed Analyzed - Analysis Complete

Insufficient Credential Protection in GitHub Copilot and VS Code

Vulnerability report for CVE-2026-47282, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-14

Last updated on: 2026-07-16

Assigner: Microsoft Corporation

Description

Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-14
Last Modified
2026-07-16
Generated
2026-08-03
AI Q&A
2026-07-14
EPSS Evaluated
2026-08-02
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
microsoft visual_studio_code to 1.128.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CWE-522 The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-47282 is a vulnerability related to insufficiently protected credentials in GitHub Copilot and Visual Studio Code. This means that sensitive credentials or authentication tokens may not be adequately secured within these applications.

An unauthorized attacker could exploit this weakness to disclose information over a network. The vulnerability allows the attacker to access sensitive data without proper authorization, potentially leading to further compromise.

Detection Guidance

The provided context does not specify exact detection methods or commands for identifying this vulnerability on a network or system. Detection would typically involve checking for exposed credentials or unauthorized access patterns related to GitHub Copilot and Visual Studio Code, but no specific tools or commands are mentioned.

You may monitor network traffic for unusual credential transmission or inspect Visual Studio Code and GitHub Copilot configurations for improperly stored credentials. However, the context does not provide actionable detection steps.

Impact Analysis

If you use GitHub Copilot or Visual Studio Code, this vulnerability could expose your credentials or other sensitive information to an attacker.

  • An attacker could gain unauthorized access to your accounts or systems if credentials are disclosed.
  • Sensitive data, such as API keys or authentication tokens, could be leaked, leading to potential misuse.
  • The vulnerability could be exploited remotely over a network, increasing the risk of exposure.
Compliance Impact

This vulnerability may impact compliance with several standards and regulations, depending on the nature of the data exposed.

  • GDPR: If the disclosed information includes personal data of EU citizens, this could constitute a breach under GDPR, leading to potential fines and mandatory reporting.
  • HIPAA: If the exposed credentials or data relate to protected health information (PHI), this could violate HIPAA regulations, resulting in penalties and required remediation.
  • Other standards, such as PCI DSS, may also be affected if payment-related credentials or data are exposed.

Organizations should assess whether the vulnerability led to unauthorized access or disclosure of regulated data and take appropriate steps to mitigate risks and report incidents if required.

Mitigation Strategies

The provided context does not detail specific mitigation steps for CVE-2026-47282. However, general best practices for mitigating insufficiently protected credentials include:

  • Apply any available patches or updates from Microsoft for GitHub Copilot and Visual Studio Code, as referenced in Resource 1.
  • Review and secure credential storage mechanisms in affected applications to ensure credentials are encrypted or properly protected.
  • Monitor network traffic for unauthorized access attempts or credential leakage.
  • Follow Microsoft's official guidance on the vulnerability, which may include additional mitigation steps (see Resource 1).

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-47282. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart