6.5
CVE-2026-69375
- EPSS 0.59%
- Veröffentlicht 08.09.2026 17:12:46
- Zuletzt bearbeitet 29.09.2026 15:55:25
- Erkennungen
Microsoft Exchange Server Tampering Vulnerability
Authorization bypass through user-controlled key in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Exchange Server Version 2016 Update cumulative_update_23
Microsoft ≫ Exchange Server Version 2019 Update cumulative_update_14
Microsoft ≫ Exchange Server Version 2019 Update cumulative_update_15
Microsoft ≫ Exchange Server Subscription Edition Version < 15.02.2562.049
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.59% | 0.463 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| Microsoft | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
|
CWE-639 Authorization Bypass Through User-Controlled Key
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69375