HarborGuardharborguardDatabase
Back to search
HIGHCVE-2026-45644Published Modified CNA microsoft

CVE-2026-45644: Microsoft Live Share Canvas SDK Elevation of Privilege Vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Live Share Canvas SDK allows an authorized attacker to elevate privileges over a network.

Metrics

CVSS v3.1
8.0
Severity
HIGH
Fixed in
1.4.2
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

A stored or reflected cross-site scripting (XSS) vulnerability exists in the Microsoft Live Share Canvas SDK, affecting versions 1.0.0 through 1.4.1. The flaw is reachable over the network and requires a low-privilege account plus a victim taking some action, such as viewing or interacting with attacker-controlled canvas content. Successful exploitation gives the attacker full control over confidentiality, integrity, and availability in the affected session, effectively elevating their privileges. A patched-image rebuild at version 1.4.2 is available on HarborGuard for environments running an affected version.

HarborGuard Coverage

Detection

Detection capability is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against customer images, including custom-built images that bundle the Microsoft Live Share Canvas SDK. Any image containing a version of the SDK below 1.4.2 is flagged automatically.

Available
Triage

HarborGuard is capable of scoring this finding at CVSS 8.0 (HIGH) and weighting it against each environment's compliance policy to determine urgency. Triage results are routed to the appropriate team inbox within each customer organization based on configured ownership rules.

Available
Patch

A patched-image rebuild at version 1.4.2 becomes available through HarborGuard once an affected image is identified. For customers who opt into auto-remediation, HarborGuard performs the rebuild, runs a regression test suite, and opens a pull request against affected workloads.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker must reach the vulnerable service over the network; there is no local or physical access requirement.

  • AuthenticationRequired

    A low-privilege authenticated account is sufficient; the attacker does not need administrative credentials.

  • Victim interactionRequired

    A victim must take some action, such as loading or interacting with attacker-controlled canvas content, for the exploit to succeed.

  • Attack complexityDetail

    Attack complexity is low, meaning the exploit is reliable and does not depend on race conditions or specific environmental configurations.

Blast Radius

  • A successful attacker reads sensitive data accessible in the victim's session context, such as session tokens or shared canvas content.
  • The attacker modifies data or injects persistent content within the victim's session, potentially affecting other users who view the same canvas.
  • The attacker can disrupt availability of the affected session or canvas workspace, preventing legitimate access.
  • Privilege escalation means the attacker operates with permissions beyond their original low-privilege account, expanding the scope of any follow-on actions.

How HarborGuard Handles This

Available on HarborGuard: detection against this CVE is active and matches any image shipping Microsoft Live Share Canvas SDK versions 1.0.0 through 1.4.1. Where compliance policy permits, HarborGuard can rebuild affected images at version 1.4.2 automatically. For customers with auto-remediation enabled, the workflow includes a regression test run and a pull request opened against affected workloads; median time from CVE publication to merged patch PR for high-severity issues is around 90 minutes in those environments. For environments where auto-remediation is not enabled, the finding is queued for manual review with the CVSS 8.0 HIGH score and ownership routing applied. In the interim, consider isolating services that embed the SDK behind network policies that restrict who can submit canvas input, and review access controls to limit the pool of authenticated users who can interact with shared canvas sessions.

See how HarborGuard automates this
Affected packages
  • Microsoft / Microsoft Live Share Canvas SDK
    < 1.4.2 (from 1.0.0)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C