Description
Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network.
Published: 2026-07-24
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Microsoft Graph enables an attacker with legitimate credentials to retrieve sensitive information that should be restricted, resulting in confidentiality loss. The exploit occurs due, allowing access to data that is not intended for the requesting user or client. The vulnerability is identified as CWE‑200, indicating it is an information‑disclosure weakness.

Affected Systems

Microsoft Graph, the cloud‑based API service from Microsoft, is affected. No specific product versions are listed in the CVE data, so the issue may exist across all current releases that implement the vulnerable authorization logic.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity, while an EPSS score of less than 1% points to a very low probability of exploitation in the wild. The flaw is not listed in CISA’s KEV catalog, suggesting no known active exploitation. Inferred from the description, the attack vector requires an authenticated participant to use certain Graph API endpoints with over‑privileged scopes, enabling disclosure of sensitive data over the network to an unauthorized actor.

Generated by OpenCVE AI on August 3, 2026 at 20:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft update that fixes the authorization bug in Microsoft Graph.
  • Enable least‑privilege for all Graph API permissions and remove any excess scopes from client applications.
  • Monitor Graph API traffic for unusual data requests and set alerts on excessive data transfer to detect potential exploitation.

Generated by OpenCVE AI on August 3, 2026 at 20:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 24 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Description Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network.
Title Microsoft Graph Information Disclosure Vulnerability
First Time appeared Microsoft
Microsoft graph
Weaknesses CWE-200
CPEs cpe:2.3:a:microsoft:graph:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft graph
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C'}


cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-10T17:21:30.756Z

Reserved: 2026-05-27T23:44:09.622Z

Link: CVE-2026-49159

cve-icon Vulnrichment

Updated: 2026-07-24T22:08:21.329Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-24T01:16:40.230

Modified: 2026-07-29T14:16:24.510

Link: CVE-2026-49159

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T21:00:12Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor