Description
Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.
Published: 2026-08-20
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Microsoft Fabric contains a relative path traversal flaw that permits an authorized attacker to access files outside the intended directory structure. By exploiting this weakness, the attacker can bypass existing authorization checks and elevate their privileges within the fabric environment. The vulnerability specifically enables the transition from an authorized user role to a higher‑privilege state, compromising the confidentiality, integrity, and availability of the affected system.

Affected Systems

Microsoft Fabric, as distributed by Microsoft. No specific version range is published in the advisory; all releases prior to the latest patch are considered vulnerable.

Risk and Exploitability

The vulnerability has a CVSS score of 9.9, indicating a critical impact and a high probability of exploitation if an attacker has legitimate network access. EPSS data is not available, and the flaw has not been listed in CISA's known exploited vulnerabilities catalog. Because the attack requires an authorized network presence, the threat is most significant to internal users or compromised accounts with limited initial privileges. Exploitation would involve crafting path traversal sequences to obtain elevated privileges across the fabric service. Given the severity and the lack of mitigation guidance, the risk remains elevated until the official patch is applied.

Generated by OpenCVE AI on August 21, 2026 at 00:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft Fabric update that resolves the path traversal flaw.
  • Limit the use of privileged accounts and enforce least‑privilege for all Fabric users.
  • Verify that directory traversal checks are in place and that file access permissions are correctly restricted.

Generated by OpenCVE AI on August 21, 2026 at 00:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 04 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft fabric
CPEs cpe:2.3:a:microsoft:fabric:-:*:*:*:*:*:*:*
Vendors & Products Microsoft fabric

Fri, 21 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Description Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.
Title Microsoft Fabric Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft microsoft Fabric
Weaknesses CWE-23
CPEs cpe:2.3:a:microsoft:microsoft_fabric:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft microsoft Fabric
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Fabric Microsoft Fabric
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-09T19:38:33.699Z

Reserved: 2026-07-16T22:05:22.739Z

Link: CVE-2026-63509

cve-icon Vulnrichment

Updated: 2026-08-21T15:36:05.418Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-20T22:17:46.963

Modified: 2026-09-04T19:11:07.640

Link: CVE-2026-63509

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T01:45:07Z

Weaknesses
  • CWE-23

    Relative Path Traversal