ZeroHour

CVE-2026-70178

mass

Missing Authorization in Microsoft Fabric Allows Network Privilege Escalation

CVSS 3.1
8.8 high
EPSS
<1%p36
Published
()
Modified
AI analysis

CVE-2026-70178 is a missing authorization flaw (CWE-862) in Microsoft Fabric in which the service fails to verify whether a user is actually permitted to perform certain privileged actions. It is triggered over the network: an attacker who already holds low-privileged, authorized access to a Fabric tenant sends crafted requests, and because the authorization check is absent, the service executes them as if they were privileged. Successful exploitation yields elevation of privilege with high impact on confidentiality, integrity, and availability within the affected tenant, with no user interaction required. Any organization using Microsoft Fabric is in scope, with exposure concentrated in tenants where low-privilege users are provisioned. Exploitation has not been observed: there is no public proof-of-concept, the CVE is not in CISA's KEV, and EPSS assigns only a 0.4% probability of exploitation in the next 30 days.

What to do: Confirm your tenant has received the September 2026 security updates referenced in Microsoft's Security Update Review; because Fabric is cloud-delivered, most tenants inherit fixes automatically, but check the Microsoft 365 admin center service health and the Microsoft advisory for component-specific notes. Audit role assignments and enforce least privilege for Fabric users, since any authenticated low-privileged user is the attack vector, and monitor for updated guidance or workarounds from Microsoft.

Affected
microsoft Fabric
Estimated exposure
masslikely millions of users across tens of thousands of tenant organizations (estimate) — Microsoft Fabric is Microsoft's unified analytics SaaS bundled with Microsoft 365/Power BI licensing and has been reported by Microsoft as adopted by tens of thousands of organizations, implying a plausible user base in the millions,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Missing authorization in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.

Vendors
microsoft
Products
fabric
Weakness
CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

The September 2026 Security Update Review

ZDI's September 2026 Microsoft update review lists two already-exploited Windows EoP zero-days and dozens of critical RCEs across Office, SQL Server, and Windows services.

The review catalogs Microsoft's September 2026 fixes, marking CVE-2026-85880 (Windows ALPC) and CVE-2026-81963 (Windows Update Stack) as already exploited elevation-of-privilege issues. It also lists critical RCE flaws in Office, Word, Excel, PowerPoint, Outlook, SQL Server, Windows DNS, DHCP and Failover Cluster, plus graphics component RCEs. Azure-side fixes include Entra ID, Copilot Studio, Azure AI Language and Azure AD B2C elevation-of-privilege flaws.