Impact
The vulnerability is a Server‑Side Request Forgery flaw (CWE‑918) in Microsoft Exchange Server that allows an authorized attacker to perform spoofing over a network. An attacker with legitimate credentials can send requests that the server forwards internally, enabling control over forged communications.
Affected Systems
The vulnerability affects Microsoft Exchange Server 2016 Cumulative Update 23, Exchange Server 2019 Cumulative Update 14, Exchange Server 2019 Cumulative Update 15, and Exchange Server Subscription Edition RTM. All listed versions remain vulnerable until the corresponding cumulative update or patch for CVE‑2026‑45501 is applied.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score is less than 1% (~0.003) and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is network‑based; a user with valid credentials can trigger the SSRF flaw by sending requests that the server forwards internally, enabling spoofed communications. Because it requires authorized access, the risk is elevated in environments with exposed authenticated users, but applying vendor patch remains the only definitive mitigation.
OpenCVE Enrichment