AI analysis
CVE-2026-70178 is a missing authorization flaw (CWE-862) in Microsoft Fabric in which the service fails to verify whether a user is actually permitted to perform certain privileged actions. It is triggered over the network: an attacker who already holds low-privileged, authorized access to a Fabric tenant sends crafted requests, and because the authorization check is absent, the service executes them as if they were privileged. Successful exploitation yields elevation of privilege with high impact on confidentiality, integrity, and availability within the affected tenant, with no user interaction required. Any organization using Microsoft Fabric is in scope, with exposure concentrated in tenants where low-privilege users are provisioned. Exploitation has not been observed: there is no public proof-of-concept, the CVE is not in CISA's KEV, and EPSS assigns only a 0.4% probability of exploitation in the next 30 days.
What to do: Confirm your tenant has received the September 2026 security updates referenced in Microsoft's Security Update Review; because Fabric is cloud-delivered, most tenants inherit fixes automatically, but check the Microsoft 365 admin center service health and the Microsoft advisory for component-specific notes. Audit role assignments and enforce least privilege for Fabric users, since any authenticated low-privileged user is the attack vector, and monitor for updated guidance or workarounds from Microsoft.
Estimated exposure
masslikely millions of users across tens of thousands of tenant organizations (estimate) — Microsoft Fabric is Microsoft's unified analytics SaaS bundled with Microsoft 365/Power BI licensing and has been reported by Microsoft as adopted by tens of thousands of organizations, implying a plausible user base in the millions,…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.