CVE-2026-94510

critical
Assigned by CNA: microsoft
Published 2026-10-08 · Modified 2026-10-08
CVSS v3
9.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:L/E:U/RL:O/RC:C
CVSS v4 NEW
—
not yet in upstream
VIR risk
9.9

Description

Authorization bypass through user-controlled key in Microsoft Bookings allows an unauthorized attacker to elevate privileges over a network.

Predictions

Exploit likelihood
98%
Patch ETA
—

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Microsoft Security Response Center · View original ↗ · proprietary-no-redistribution
Full prose not cached — VIR stores only structured fields (affected/fixed versions, references) for this source. Click "View original" above for the vendor's full advisory.

Affected

VendorProductVersion
microsoftAzure API Center
microsoftAzure App Service for Linux
microsoftMicrosoft Exchange Server 2016 Cumulative Update 23
microsoftMicrosoft Exchange Server 2019 Cumulative Update 14
microsoftMicrosoft Dataverse
microsoftMicrosoft Partner Center
microsoftMicrosoft Exchange Server 2019 Cumulative Update 15
microsoftMicrosoft Exchange Server Subscription Edition RTM
microsoftAzure Event Grid System
microsoftAzure SRE Agent
microsoftazl3 thrift 0.24.0-1 on Azure Linux 3.0
microsoftazl3 opensc 0.27.1-2 on Azure Linux 3.0
microsoftazl3 gnupg2 2.4.9-3 on Azure Linux 3.0
microsoftazl3 clamav 1.5.4-2 on Azure Linux 3.0
microsoftazl3 influxdb 2.7.5-21 on Azure Linux 3.0
microsoftazl3 telegraf 1.31.0-33 on Azure Linux 3.0
microsoftazl3 kata-containers 4.1.0.kata0-1 on Azure Linux 3.0
microsoftazl3 kata-containers-cc 3.15.0.aks0-21 on Azure Linux 3.0
microsoftazl3 kernel 6.6.157.1-1 on Azure Linux 3.0

OS impact

windows Windows Affected 1 release
VersionStatusFixed in
— Affected —

References

CWEs

CWE-639

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.