ZeroHour

CVE-2026-69843

mass

Authentication Bypass by Spoofing in Microsoft Fabric

CVSS 3.1
10.0 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-69843 is an authentication bypass by spoofing flaw (CWE-290) in Microsoft Fabric, Microsoft's cloud analytics platform. An unauthenticated remote attacker can trigger it by sending spoofed network requests that impersonate a legitimate trusted identity or endpoint, requiring no user interaction or credentials. Successful exploitation grants the attacker elevated privileges over the network, with the scope-changed CVSS vector indicating potential high impact to confidentiality, integrity, and availability beyond the vulnerable component. Any organization using Microsoft Fabric is in the affected population. As of this writing there is no known in-the-wild exploitation, no CISA KEV listing, and no public proof-of-concept.

What to do: Confirm your Microsoft 365/Fabric tenant has received Microsoft's remediation (cloud components are patched by Microsoft, but any customer-hosted components such as data gateways must be updated per Microsoft's advisory). Review Fabric/Microsoft Entra sign-in and audit logs for anomalous access or unexpected privilege elevation, and rotate credentials for privileged service accounts. Restrict network paths into Fabric-connected resources and follow Microsoft's advisory for additional mitigations.

Affected
Microsoft Fabric (cloud analytics platform)
Estimated exposure
massmillions of users across roughly 25,000+ customer organizations (Microsoft-reported Fabric adoption) — Microsoft has publicly reported Fabric surpassed ~25,000 paying customers shortly after general availability and it inherits the very large Power BI user base (hundreds of thousands of organizations), so a user population in the millions…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Authentication bypass by spoofing in Microsoft Fabric allows an unauthorized attacker to elevate privileges over a network.

Weakness
CWE-290
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.