Junglewise Threat Intelligence

CVE-2026-41104: Microsoft Planetary Computer Pro deserialization of untrusted data

CVE-2026-41104 · Severity: critical · CVSS 10 · Published 2026-05-22

Vendors: Microsoft.

Executive brief

Microsoft Planetary Computer Pro, a platform used for environmental data analysis and geospatial computing, contains a critical security flaw. An unauthorized attacker can exploit this vulnerability over the network to gain access to sensitive information. This could lead to a total compromise of the service, including data theft and loss of operational control.

Technical details

A critical deserialization vulnerability (CWE-502) exists in Microsoft Planetary Computer Pro. The flaw allows for the processing of untrusted data, which can be exploited by an unauthenticated attacker over a network. According to the CVSS 3.1 vector, the vulnerability has a low attack complexity, requires no user interaction, and results in a scope change with high impacts on confidentiality, integrity, and availability. This suggests the potential for remote code execution or full system compromise. Users should refer to the Microsoft Security Update Guide for specific mitigation or patching instructions.

Affected products

  • Microsoft Planetary Computer Pro

Timeline

  • 2026-05-22: disclosed
  • 2026-05-22: advisory: MSRC advisory published

References