CVE-2026-69641
massMissing Authorization Privilege Escalation in Microsoft Exchange Server
Microsoft Exchange Server contains a missing authorization flaw (CWE-862), meaning a privileged operation does not properly verify whether the caller is permitted to perform it. The flaw is reachable over the network, and the CVSS vector indicates the attacker must already hold high privileges (PR:H) — e.g., an Exchange administrator-level account — before triggering it, with impact extending beyond the vulnerable component's security scope (S:C). A successful attacker elevates their privileges into a broader scope, with high impact on confidentiality, integrity, and availability. Any organization running Microsoft Exchange Server is potentially affected; the available data does not enumerate specific affected versions or builds. There is currently no known public proof-of-concept, no CISA KEV listing, and EPSS estimates only about a 0.8% probability of exploitation within 30 days, so exploitation is not yet observed.
What to do: Apply the Microsoft security update for Exchange Server addressing CVE-2026-69641 when available, and verify your installed build against the affected-versions table in Microsoft's advisory (not enumerated in this data). Until patched, restrict and audit high-privileged Exchange administrative accounts, since exploitation requires that level of access, and monitor logs for unexpected privilege or scope changes. Watch this dashboard for changes in EPSS or KEV status that would indicate active exploitation.
| Microsoft Exchange Server | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
- Weakness
- CWE-862
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.