Junglewise Threat Intelligence

CVE-2026-48582: Microsoft Exchange Online privilege escalation via missing authorization

CVE-2026-48582 · Severity: critical · CVSS 9.6 · Published 2026-06-19

Technologies: Microsoft Exchange Online. Vendors: Microsoft.

Executive brief

Microsoft Exchange Online, the cloud-based email and calendaring service, contains a security flaw that allows an existing user to gain unauthorized administrative permissions. By exploiting this weakness, an attacker with basic access to the organization's network can escalate their privileges to perform high-level actions they should not be allowed to do. This could lead to the unauthorized access of sensitive corporate emails, data theft, or full control over the organization's email environment.

Technical details

A privilege escalation vulnerability exists in Microsoft Exchange Online due to missing authorization checks (CWE-862). An attacker who is already authenticated to the network with low-level permissions can exploit this flaw to gain elevated privileges. The vulnerability has a CVSS 3.1 score of 9.6, characterized by a network attack vector, low complexity, and a scope change, indicating that the attacker can impact components beyond the initial security scope. Successful exploitation allows for high confidentiality and integrity impacts. As this is a cloud-hosted service, Microsoft typically manages the deployment of fixes directly on the platform.

Affected products

  • Microsoft Exchange Online All versions

Timeline

  • 2026-06-19: disclosed: Initial disclosure by Microsoft and NVD
  • 2026-06-19: advisory

References

Related threats