Executive brief
A critical vulnerability has been identified in Microsoft Exchange Online, the cloud-based email and calendaring service used by organizations worldwide. This flaw allows an unauthorized person to access sensitive information over the internet without needing any login credentials. Exploitation could lead to the exposure of private communications or corporate data, potentially resulting in significant privacy breaches and operational risks.
Technical details
A vulnerability classified as Improper Authorization (CWE-285) exists in Microsoft Exchange Online. The flaw allows a remote, unauthenticated attacker to bypass authorization checks and disclose sensitive information over the network. According to the CVSS vector, the attack complexity is low and requires no user interaction, posing a high risk to data confidentiality and integrity. As this is an exclusively hosted service, Microsoft typically manages the deployment of fixes directly within the Exchange Online environment.
Affected products
- Microsoft Exchange Online
Timeline
- 2026-06-04: advisory: Initial advisory published by Microsoft and NVD.