Impact
A flaw in Microsoft Graph enables an attacker with legitimate credentials to retrieve sensitive information that should be restricted, resulting in confidentiality loss. The exploit occurs due, allowing access to data that is not intended for the requesting user or client. The vulnerability is identified as CWE‑200, indicating it is an information‑disclosure weakness.
Affected Systems
Microsoft Graph, the cloud‑based API service from Microsoft, is affected. No specific product versions are listed in the CVE data, so the issue may exist across all current releases that implement the vulnerable authorization logic.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while an EPSS score of less than 1% points to a very low probability of exploitation in the wild. The flaw is not listed in CISA’s KEV catalog, suggesting no known active exploitation. Inferred from the description, the attack vector requires an authenticated participant to use certain Graph API endpoints with over‑privileged scopes, enabling disclosure of sensitive data over the network to an unauthorized actor.
OpenCVE Enrichment