Improper authorization in Microsoft Exchange Online allows an unauthorized attacker to disclose information over a network.
The error classified as CWE-285 (Improper Authorization) means that access control mechanisms in Microsoft Exchange Online do not properly verify the requestor's permissions. An attacker without an account or any privileges can send a specially crafted network request that bypasses access control. As a result, the service returns resources or data that should have restricted access.
An attacker can gain unauthorized access to sensitive information stored or processed by Microsoft Exchange Online, such as emails, mailbox metadata, or organizational data. The attack vector is network-based and does not require authentication or user interaction, indicating high risk of widespread exploitation.
As a cloud service, Microsoft Exchange Online is managed by Microsoft — organizations should monitor security messages in the Microsoft Security Response Center (MSRC) at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48579 and apply any configuration recommendations provided by the vendor. Patches on the service infrastructure side are deployed by Microsoft.
Microsoft Exchange Online — versions specified in vendor references
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NMicrosoft Exchange Online
APPMicrosoftall versions
Related vulnerabilities
Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate pri...
Obejście uwierzytelnienia w Microsoft Exchange Online (RCE/Tampering)
Brak autoryzacji w Microsoft Exchange Online umożliwia privilege escalation
Błędna autoryzacja w Microsoft Exchange Online — privilege escalation
RCE przez deserializację niezaufanych danych w Microsoft SharePoint