Description
Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network.
Published: 2026-07-02
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An incorrect authorization check in Microsoft Exchange Online allows an attacker who already has valid credentials to elevate his or her privileges. The flaw is specifically tied to an authorization misconfiguration (CWE-863) that permits a higher level of access than intended for that user. The description does not state any additional capabilities beyond the privilege increase, and no specific remote execution or data exfiltration is mentioned.

Affected Systems

Microsoft Exchange Online is affected. No version or detailed product variations are listed in the current data.

Risk and Exploitability

The vulnerability has a CVSS score of 8.8, indicating a high severity. The EPSS score is less than 1%, suggesting a low probability of exploitation. It is not included in the CISA KEV catalog. The likely attack route is over the network, where an authenticated attacker can exploit the authorization flaw to raise privileges.

Generated by OpenCVE AI on July 21, 2026 at 10:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Microsoft patch that addresses CVE-2026-54998 for Exchange Online.
  • Review and tighten any privileged roles or permissions in the Exchange Online environment to enforce least privilege.
  • Enable comprehensive auditing of privileged endpoint activity and monitor logs for anomalous privilege changes or usage.

Generated by OpenCVE AI on July 21, 2026 at 10:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Description Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network.
Title Microsoft Exchange Online Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft exchange Online
Weaknesses CWE-863
CPEs cpe:2.3:a:microsoft:exchange_online:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft exchange Online
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Exchange Online
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-22T20:29:07.726Z

Reserved: 2026-06-16T14:10:05.869Z

Link: CVE-2026-54998

cve-icon Vulnrichment

Updated: 2026-07-06T15:33:40.576Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T10:45:02Z

Weaknesses