Executive brief
Microsoft Discovery Studio is a data analysis and visualization tool used by researchers and enterprises to explore complex datasets. A flaw in how the tool processes database queries allows attackers to craft malicious inputs that bypass security controls and extract sensitive information without authorization. This could expose confidential research data, business intelligence, or other sensitive information stored within the application.
Technical details
The vulnerability is an improper neutralization of special elements in data query logic (CWE-89 class, similar to injection flaws). An attacker can inject specially-crafted input into query parameters that is not properly sanitized before being processed by the backend, allowing unauthorized data access. The attack is network-reachable and does not require prior authentication. By exploiting this query injection flaw, an attacker can retrieve sensitive information stored in the application's database. The CVSS score of 7.4 reflects high impact on confidentiality with network accessibility.
Affected products
- Microsoft Discovery Studio
Timeline
- 2026-09-03: disclosed