Executive brief
Microsoft Graph, the primary gateway for accessing data and intelligence across Microsoft 365 services, contains a vulnerability that could allow unauthorized access to sensitive information. An attacker with basic user credentials on the network could exploit this flaw to view data they are not permitted to see. This could lead to the exposure of confidential organizational data or personal user information stored within the Microsoft cloud ecosystem.
Technical details
An information disclosure vulnerability exists in Microsoft Graph, classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). The flaw allows an attacker with low-level 'Authorized' privileges to disclose sensitive information over a network. According to the CVSS vector, the attack is low complexity, requires no user interaction, and has a high impact on confidentiality. As Microsoft Graph is an exclusively hosted service, the fix is typically managed by the provider on the backend.
Affected products
- Microsoft Microsoft Graph All versions
Timeline
- 2026-07-24: advisory: Initial disclosure by Microsoft and NVD