CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2026-48579

CVSS 9.1v3.1pub. 2026-06-04upd. 2026-06-05

Improper authorization in Microsoft Exchange Online allows an unauthorized attacker to disclose information over a network.

🤖 AI Analysis
How it works

The error classified as CWE-285 (Improper Authorization) means that access control mechanisms in Microsoft Exchange Online do not properly verify the requestor's permissions. An attacker without an account or any privileges can send a specially crafted network request that bypasses access control. As a result, the service returns resources or data that should have restricted access.

Impact

An attacker can gain unauthorized access to sensitive information stored or processed by Microsoft Exchange Online, such as emails, mailbox metadata, or organizational data. The attack vector is network-based and does not require authentication or user interaction, indicating high risk of widespread exploitation.

Mitigation & patch

As a cloud service, Microsoft Exchange Online is managed by Microsoft — organizations should monitor security messages in the Microsoft Security Response Center (MSRC) at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48579 and apply any configuration recommendations provided by the vendor. Patches on the service infrastructure side are deployed by Microsoft.

Who is affected

Microsoft Exchange Online — versions specified in vendor references

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  • Microsoft Exchange Online

    APP
    Microsoft
    all versions
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2026-65801CRITICAL10.0same product

Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate pri...

CVE-2026-56191CRITICAL10.0PL ✓same product

Obejście uwierzytelnienia w Microsoft Exchange Online (RCE/Tampering)

CVE-2026-48582CRITICAL9.6PL ✓same product

Brak autoryzacji w Microsoft Exchange Online umożliwia privilege escalation

CVE-2026-54998HIGH8.8PL ✓same product

Błędna autoryzacja w Microsoft Exchange Online — privilege escalation

CVE-2026-50522CRITICAL9.8⚠ KEVPL ✓same vendor

RCE przez deserializację niezaufanych danych w Microsoft SharePoint