Junglewise Threat Intelligence

CVE-2026-26145: Microsoft Azure Synapse improper access control privilege escalation

CVE-2026-26145 · Severity: medium · CVSS 4.8 · Published 2026-07-02

Vendors: Microsoft.

Executive brief

Microsoft Azure Synapse Analytics, a data analytics service used by enterprises to process and analyze large datasets, contains a security vulnerability that could allow an authorized user to gain higher levels of access than intended. An attacker who already has basic access to the system could exploit this flaw to view sensitive information they are not authorized to see. While the attack requires specific conditions and user interaction to succeed, it poses a risk to data confidentiality and internal access controls.

Technical details

An improper access control vulnerability (CWE-284) exists in Microsoft Azure Synapse Analytics. The flaw allows an authenticated attacker with low-level privileges to elevate their permissions over the network, potentially leading to unauthorized data disclosure. According to the CVSS vector, the attack complexity is high and requires a specific user interaction to be successful. The vulnerability is specific to the cloud-hosted service environment, and Microsoft typically manages updates for such services directly.

Affected products

  • Microsoft Azure Synapse Analytics All versions

Timeline

  • 2026-07-02: disclosed: Initial disclosure by Microsoft and NVD

References

Related threats