Description
Lokka is a Model Context Protocol server for Microsoft 365, including Microsoft Graph and other services. Prior to 2.1.2, the Lokka-Microsoft tool in src/mcp/src/main.ts uses direct URL string concatenation to append the user-controlled path value to the management.azure.com base URL. A specially crafted path can alter URL authority parsing and cause an Azure Resource Manager bearer token to be sent to an unintended host. This issue is fixed in version 2.1.2.
Published: 2026-09-15
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Unintended bearer token transmission to an unauthorized host
Action: Patch Immediately
AI Analysis

Impact

Lokka is a Model Context Protocol server for Microsoft 365 environments. In versions prior to 2.1.2 the Lokka‑Microsoft component builds an Azure Resource Manager URL by concatenating a user‑controlled path onto the base management.azure.com address. This flaw, identified CWE‑918 (Exploitable Path Manipulation), can cause the constructed URL to resolve to an unintended host, resulting in an Azure Resource Manager bearer token being sent to that host. The CVSS score of 8.7 reflects the high severity of sending credentials to an unauthorized endpoint, while the EPSS score of less than 1% indicates a currently low likelihood of exploitation.

Affected Systems

The vulnerability affects Merill Lokka tooling running the Lokka‑Microsoft component before version 2.1.2. Any deployment of Lokka that interfaces with Microsoft Graph or other Microsoft 365 services, especially those that construct Azure Resource Manager URLs from user input, is impacted. Users running the default configuration with unpatched Lokka on the 2026-58201 timeframe are therefore at risk.

Risk and Exploitability

Exploitation would require an attacker able to supply a specially crafted URL path to the Lokka tool. The flaw would then redirect the bearer token to an unintended host, which could capture the credentials or allow lateral movement within the target environment. While the EPSS score indicates that such attacks are currently rare and the vulnerability is not listed in the CISA KEV catalog, the high CVSS score and the potential for credential leakage underscore a significant risk for systems that remain unpatched.

Generated by OpenCVE AI on September 20, 2026 at 15:15 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Lokka to version 2.1.2 to eliminate the URL concatenation flaw.
  • If an upgrade cannot be performed immediately, review any configuration or code that allows path concatenation into Azure Resource Manager URLs and remove or sanitize them to prevent unintended token delivery.
  • Apply network segmentation or firewall rules to restrict outbound connections from the Lokka service so that traffic to unauthorized hosts is blocked.

Generated by OpenCVE AI on September 20, 2026 at 15:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Merill
Merill lokka
Vendors & Products Merill
Merill lokka

Tue, 15 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
Description Lokka is a Model Context Protocol server for Microsoft 365, including Microsoft Graph and other services. Prior to 2.1.2, the Lokka-Microsoft tool in src/mcp/src/main.ts uses direct URL string concatenation to append the user-controlled path value to the management.azure.com base URL. A specially crafted path can alter URL authority parsing and cause an Azure Resource Manager bearer token to be sent to an unintended host. This issue is fixed in version 2.1.2.
Title Lokka: Azure Resource Manager URL path validation issue
Weaknesses CWE-918
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-15T19:01:50.538Z

Reserved: 2026-06-29T17:09:25.872Z

Link: CVE-2026-58201

cve-icon Vulnrichment

Updated: 2026-09-15T19:01:46.655Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T17:17:23.260

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-58201

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T15:30:17Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)