Description
Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network.
Published: 2026-08-06
Score: 10 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from missing authentication on a critical function in Microsoft Planetary Computer Pro, enabling an unauthorized attacker to elevate privileges over a network. This flaw allows an adversary to gain higher-level access than intended, potentially compromising confidentiality, integrity, and availability of planetary data services. The weakness is classified as CWE-306, indicating missing authentication controls.

Affected Systems

Affected vendors and products include Microsoft’s Planetary Computer Pro, specifically the GeoCatalog component. No version information is provided, so all deployed instances of this product are potentially impacted until a patch is applied.

Risk and Exploitability

The CVSS score of 10 denotes a critical severity, and the EPSS score is not available, but the absence of authentication makes the vulnerability highly exploitable over the network. Attackers could exploit this flaw remotely without needing credentials, making it a high-priority threat. The vulnerability is not yet listed in the CISA KEV catalog; however, its critical nature warrants prompt remediation.

Generated by OpenCVE AI on August 7, 2026 at 01:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply an official patch or update once Microsoft releases a fix for the missing authentication issue.
  • Restrict network access to the Planetary Computer Pro services by applying firewall rules or virtual network segmentation to limit exposure of the critical function to trusted networks only.
  • Disable or protect the affected endpoint until a patch is deployed, for example by enforcing authentication or temporarily blocking the API route through configuration or reverse‑proxy settings.
  • Monitor logs and audit trails for suspicious activity targeting the privileged API endpoints to detect exploitation attempts early.

Generated by OpenCVE AI on August 7, 2026 at 01:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Description Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network.
Title Microsoft Planetary Computer Pro Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft planetary Computer Pro
Weaknesses CWE-306
CPEs cpe:2.3:a:microsoft:planetary_computer_pro:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft planetary Computer Pro
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Planetary Computer Pro
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-06T23:22:13.879Z

Reserved: 2026-07-16T22:05:22.739Z

Link: CVE-2026-63508

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T01:30:04Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function