HIGH✓ PATCH🇵🇱 Wersja polska

CVE-2026-69558

CVSS 8.6v3.1pub. 2026-08-20upd. 2026-08-25

Authorization bypass through user-controlled key in Microsoft Partner Center allows an unauthorized attacker to disclose information over a network.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
  • Microsoft Partner Center

    APP
    Microsoft
    all versions
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2026-24303CRITICAL9.6PL ✓same product

Privilege Escalation w Microsoft Partner Center przez nieprawidłową kontrolę dostępu

CVE-2025-65041CRITICAL10.0PL ✓same product

Nieprawidłowa autoryzacja w Microsoft Partner Center — privilege escalation

CVE-2025-29814CRITICAL9.3PL ✓same product

Nieautoryzowana eskalacja uprawnień w Microsoft Partner Center

CVE-2024-49035HIGH8.7⚠ KEVsame product

An improper access control vulnerability in Partner.Microsoft.com allows an a unauthenticated attacker to elev...

CVE-2026-34327HIGH8.2same product

Externally controlled reference to a resource in another sphere in Microsoft Partner Center allows an unauthor...