Description
Insufficient granularity of access control in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.
Published: 2026-07-14
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Microsoft Exchange Server has a flaw in its access control that allows an attacker who already has local access to gain higher privileges on the host. The vulnerability stems from insufficient granularity in permission checks and can enable a user to obtain administrative level rights, potentially giving them full control over the local system. This weakness is classified as CWE-1220, indicating that access control scopes are not properly enforced.

Affected Systems

The affected products are Microsoft Exchange Server 2016 with cumulative update 23, Microsoft Exchange Server 2019 with cumulative updates 14 and 15, and the Exchange Server Subscription Edition in its RTM release. These versions are susceptible to the privilege escalation flaw until patched.

Risk and Exploitability

The CVSS score of 7.8 places this vulnerability in the medium to high severity range. The EPSS score of less than 1% indicates a very low probability of exploit at this time, and the issue is not listed in the CISA KEV catalog. Because the vulnerability requires local access and insufficient permission granularity, it is likely that an attacker would first need to authenticate or gain local foothold before escalating. In environments where local accounts are privileged, the risk is amplified, but the low exploitation likelihood suggests that patching should be prioritized over monitoring alone.

Generated by OpenCVE AI on July 31, 2026 at 09:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft Exchange Server cumulative updates that include the fix for CVE-2026-55006, following the guidance on the Microsoft Security Update Guide.
  • Restrict local account privileges to the minimum required for normal operation, following the principle of least privilege.
  • Enable and regularly review audit logging for elevation of privilege events, and configure alerts for suspicious local privilege changes.

Generated by OpenCVE AI on July 31, 2026 at 09:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Description Insufficient granularity of access control in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.
Title Microsoft Exchange Server Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft exchange Server 2016
Microsoft exchange Server 2019
Microsoft exchange Server Se
Weaknesses CWE-1220
CPEs cpe:2.3:a:microsoft:exchange_server_2016:*:cumulative_update_23:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server_2019:*:cumulative_update_14:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server_2019:*:cumulative_update_15:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server_se:*:RTM:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft exchange Server 2016
Microsoft exchange Server 2019
Microsoft exchange Server Se
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Exchange Server 2016 Exchange Server 2019 Exchange Server Se
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-30T20:22:38.033Z

Reserved: 2026-06-16T14:10:05.870Z

Link: CVE-2026-55006

cve-icon Vulnrichment

Updated: 2026-07-14T17:44:55.532Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T09:30:05Z

Weaknesses
  • CWE-1220

    Insufficient Granularity of Access Control