Executive brief
Microsoft Graph, the gateway to data and intelligence in Microsoft 365, contains a vulnerability that could allow an authorized user to access sensitive information they are not permitted to see. An attacker with basic user credentials could exploit this flaw over the network to disclose internal data. This could lead to the exposure of confidential organizational information, potentially impacting privacy and compliance.
Technical details
An information disclosure vulnerability exists in Microsoft Graph, classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). The flaw allows an attacker with low-privileged user accounts to bypass intended access restrictions and retrieve sensitive information via network requests. The attack vector is network-based and requires no user interaction, though the attacker must be authenticated to the service. Successful exploitation results in a high impact on confidentiality, while integrity and availability remain unaffected. As this is an exclusively hosted service, Microsoft typically manages the remediation on the backend.
Affected products
- Microsoft Graph
Timeline
- 2026-06-04: disclosed: Initial publication of CVE-2026-47655 by Microsoft.
- 2026-06-04: advisory