Description
Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network.
Published: 2026-07-24
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper authentication in Microsoft Exchange Online allows an attacker to bypass normal login controls (CWE‑287) and tamper with the service. The flaw enables unauthorized modification of email data, configuration settings, or other managed objects, potentially compromising confidentiality, integrity, and availability for the tenant.

Affected Systems

The product is Microsoft Exchange Online. No specific version range is supplied, so all deployments of Microsoft Exchange Online are potentially affected until Microsoft releases the formal fix.

Risk and Exploitability

The CVSS score of 10 signals critical severity, while the EPSS score of <1% indicates that, at the time of this analysis, the likelihood of exploitation is very low. The vulnerability is not listed in CISA KEV. The likely attack vector is remote network access, exploiting an authentication bypass to gain tampering capabilities. An attacker would send crafted authentication requests to Exchange Online, thereby manipulating messages or settings without proper authorization.

Generated by OpenCVE AI on August 3, 2026 at 20:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any Microsoft security update or patch that addresses this vulnerability to Microsoft Exchange Online immediately.
  • If a patch is not yet available, enable Multi‑Factor Authentication for all users and enforce strong password policies to reduce the likelihood of a successful authentication bypass.
  • Restrict network access to the Exchange Online service by applying firewall rules or IP whitelists, and monitor logs for abnormal authentication attempts or message tampering events.

Generated by OpenCVE AI on August 3, 2026 at 20:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 24 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Description Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network.
Title Microsoft Exchange Online Tampering Vulnerability
First Time appeared Microsoft
Microsoft exchange Online
Weaknesses CWE-287
CPEs cpe:2.3:a:microsoft:exchange_online:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft exchange Online
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Exchange Online
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-10T17:21:31.881Z

Reserved: 2026-06-19T13:54:04.006Z

Link: CVE-2026-56191

cve-icon Vulnrichment

Updated: 2026-07-24T22:09:07.842Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-24T01:17:36.417

Modified: 2026-07-29T14:55:55.733

Link: CVE-2026-56191

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T21:00:12Z

Weaknesses