Junglewise Threat Intelligence

CVE-2026-48579: Microsoft Exchange Online improper authorization

CVE-2026-48579 · Severity: critical · CVSS 9.1 · Published 2026-06-04

Technologies: Microsoft Exchange Online. Vendors: Microsoft.

Executive brief

A critical vulnerability has been identified in Microsoft Exchange Online, the cloud-based email and calendaring service used by organizations worldwide. This flaw allows an unauthorized person to access sensitive information over the internet without needing any login credentials. Exploitation could lead to the exposure of private communications or corporate data, potentially resulting in significant privacy breaches and operational risks.

Technical details

A vulnerability classified as Improper Authorization (CWE-285) exists in Microsoft Exchange Online. The flaw allows a remote, unauthenticated attacker to bypass authorization checks and disclose sensitive information over the network. According to the CVSS vector, the attack complexity is low and requires no user interaction, posing a high risk to data confidentiality and integrity. As this is an exclusively hosted service, Microsoft typically manages the deployment of fixes directly within the Exchange Online environment.

Affected products

  • Microsoft Exchange Online

Timeline

  • 2026-06-04: advisory: Initial advisory published by Microsoft and NVD.

References

Related threats