Impact
Microsoft Fabric contains a relative path traversal flaw that permits an authorized attacker to access files outside the intended directory structure. By exploiting this weakness, the attacker can bypass existing authorization checks and elevate their privileges within the fabric environment. The vulnerability specifically enables the transition from an authorized user role to a higher‑privilege state, compromising the confidentiality, integrity, and availability of the affected system.
Affected Systems
Microsoft Fabric, as distributed by Microsoft. No specific version range is published in the advisory; all releases prior to the latest patch are considered vulnerable.
Risk and Exploitability
The vulnerability has a CVSS score of 9.9, indicating a critical impact and a high probability of exploitation if an attacker has legitimate network access. EPSS data is not available, and the flaw has not been listed in CISA's known exploited vulnerabilities catalog. Because the attack requires an authorized network presence, the threat is most significant to internal users or compromised accounts with limited initial privileges. Exploitation would involve crafting path traversal sequences to obtain elevated privileges across the fabric service. Given the severity and the lack of mitigation guidance, the risk remains elevated until the official patch is applied.
OpenCVE Enrichment