Executive brief
Microsoft Exchange Online, the cloud-based email and calendaring service, contains a security flaw that allows an authorized user to gain higher levels of permission than they should have. An attacker with basic user credentials could exploit this to access sensitive data or perform administrative actions across the network. This could lead to unauthorized access to corporate communications and potential disruption of email services.
Technical details
An incorrect authorization vulnerability (CWE-863) exists in Microsoft Exchange Online. The flaw allows a remote attacker with low-privileged credentials to bypass authorization checks and elevate their privileges within the environment. The attack vector is network-based and requires no user interaction, though it does require the attacker to be authenticated to the service. Successful exploitation could result in a total loss of confidentiality, integrity, and availability (CVSS 8.8). As this is a hosted service, Microsoft typically manages the deployment of fixes directly on the platform.
Affected products
- Microsoft Exchange Online All versions
Timeline
- 2026-07-02: advisory: Initial disclosure by Microsoft and NVD.