Junglewise Threat Intelligence

CVE-2026-63509: Microsoft Fabric relative path traversal privilege escalation

CVE-2026-63509 · Severity: critical · CVSS 9.9 · Published 2026-08-20

Vendors: Microsoft.

Executive brief

Microsoft Fabric is a cloud-based analytics and data integration platform used by organizations to manage and analyze business data. A relative path traversal vulnerability allows authorized users to exploit the system's file handling logic to escalate their privileges beyond their intended access level, potentially gaining administrative control and access to sensitive data across the platform.

Technical details

This vulnerability is a relative path traversal flaw in Microsoft Fabric that permits privilege escalation. An authenticated attacker can craft requests containing relative path sequences (e.g., "../") to bypass authorization checks and access resources or functionality restricted to higher-privileged roles. The vulnerability is network-reachable and requires valid authentication credentials; no additional user interaction is needed. A successful exploit allows an attacker to escalate from their current privilege level to a higher one, potentially gaining administrative capabilities. Microsoft has released patches to address this issue.

Affected products

  • Microsoft Fabric <UNKNOWN>

Timeline

  • 2026-08-20: disclosed

References