Junglewise Threat Intelligence

CVE-2026-49159: Microsoft Microsoft Graph information disclosure

CVE-2026-49159 · Severity: medium · CVSS 6.5 · Published 2026-07-24

Vendors: Microsoft.

Executive brief

Microsoft Graph, the primary gateway for accessing data and intelligence across Microsoft 365 services, contains a vulnerability that could allow unauthorized access to sensitive information. An attacker with basic user credentials on the network could exploit this flaw to view data they are not permitted to see. This could lead to the exposure of confidential organizational data or personal user information stored within the Microsoft cloud ecosystem.

Technical details

An information disclosure vulnerability exists in Microsoft Graph, classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). The flaw allows an attacker with low-level 'Authorized' privileges to disclose sensitive information over a network. According to the CVSS vector, the attack is low complexity, requires no user interaction, and has a high impact on confidentiality. As Microsoft Graph is an exclusively hosted service, the fix is typically managed by the provider on the backend.

Affected products

  • Microsoft Microsoft Graph All versions

Timeline

  • 2026-07-24: advisory: Initial disclosure by Microsoft and NVD

References

Related threats