Junglewise Threat Intelligence

CVE-2026-57205: Microsoft SimpleChat IDOR in user profile endpoints

CVE-2026-57205 · Severity: medium · CVSS 4.3 · Published 2026-07-16

Vendors: Microsoft.

Executive brief

Microsoft SimpleChat, an AI conversation platform for document-based collaboration, contained a security flaw that allowed users to view private profile information of other users. By manipulating web requests, an authenticated user could access the email addresses, display names, and profile images of colleagues without permission. This could lead to unauthorized data collection and privacy violations within an organization.

Technical details

An Insecure Direct Object Reference (IDOR) vulnerability exists in the GET /api/user/info/<user_id> and GET /api/user/profile-image/<user_id> endpoints within 'application/single_app/route_backend_users.py'. The application failed to perform object-level authorization checks after verifying the caller's authentication status. An attacker with low-level authenticated access could provide a target user's Entra object ID to retrieve their Cosmos DB user-settings document, exposing email addresses, display names, and profile images. The issue is resolved in version 0.241.203 by implementing an authorization boundary that restricts profile access to the user themselves, administrators, or verified collaborators.

Affected products

  • Microsoft SimpleChat < 0.241.203

Timeline

  • 2026-06-17: advisory: GitHub Security Advisory published
  • 2026-06-25: patched: Version 0.250.001 released containing the fix
  • 2026-07-16: disclosed: CVE-2026-57205 published to NVD

References

Related threats