Junglewise Threat Intelligence

CVE-2026-47633: Microsoft Cost Management sensitive information disclosure

CVE-2026-47633 · Severity: high · CVSS 7.5 · Published 2026-06-18

Vendors: Microsoft.

Executive brief

A vulnerability in Microsoft Cost Management Interactive Experiences allows unauthorized individuals to access sensitive information over the network. This tool is used by organizations to track and manage cloud spending; an exploit could lead to the exposure of private financial or operational data. No user interaction or special privileges are required for an attacker to trigger this disclosure.

Technical details

A sensitive information disclosure vulnerability (CWE-200) exists in Microsoft Cost Management Interactive Experiences. The flaw allows an unauthenticated attacker to access data over a network without any prior authorization or user interaction. According to the CVSS vector, the attack complexity is low and the impact is limited to confidentiality, with no direct impact on system integrity or availability. As this is an exclusively hosted service, Microsoft typically applies fixes directly to the cloud environment.

Affected products

  • Microsoft Cost Management Interactive Experiences All versions

Timeline

  • 2026-06-18: disclosed
  • 2026-06-18: advisory

References