Description
Improper access control in Microsoft Purview eDiscovery allows an authorized attacker to elevate privileges over a network.
Published: 2026-08-06
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from improper access control (CWE‑284) within Microsoft Purview eDiscovery, enabling an authorized user to elevate their privileges over the network. An attacker who already has authorized access can exploit this flaw to gain higher level rights, potentially allowing them to access restricted data or manipulate the system. The flaw does not directly expose data or services, but it provides a path to broaden an attacker’s capabilities within the Purview environment.

Affected Systems

Microsoft Purview eDiscovery is affected by this vulnerability. No specific version information is provided, so all deployments of Purview eDiscovery potentially carry the risk until a patch is applied.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity, while the EPSS score is not available and it is not listed in CISA's KEV catalog. The likely attack vector requires an authenticated user over the network, as the description notes an authorized attacker can elevate privileges. Exploitation would involve leveraging existing legitimate access rights and bypassing internal controls to assume higher privileges, which could compromise data confidentiality and integrity. The lack of a public exploitation indicator suggests that, although the risk is high, out‑of‑band exploitation has not yet been observed.

Generated by OpenCVE AI on August 7, 2026 at 01:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft update for Purview eDiscovery that contains the fix for this access‑control flaw.
  • Audit and enforce the principle of least privilege by reviewing role assignments and removing any unnecessary elevated permissions.
  • Enable and regularly review audit logs for privilege escalation events to detect potential misuse early.

Generated by OpenCVE AI on August 7, 2026 at 01:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 02:00:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft purview Ediscovery
Vendors & Products Microsoft purview Ediscovery

Fri, 07 Aug 2026 01:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 07 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Description Improper access control in Microsoft Purview eDiscovery allows an authorized attacker to elevate privileges over a network.
Title Microsoft Purview eDiscovery Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft office Purview Ediscovery
Weaknesses CWE-284
CPEs cpe:2.3:a:microsoft:office_purview_ediscovery:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft office Purview Ediscovery
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Office Purview Ediscovery Purview Ediscovery
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-27T18:31:48.314Z

Reserved: 2026-07-22T18:16:01.897Z

Link: CVE-2026-65668

cve-icon Vulnrichment

Updated: 2026-08-07T01:06:21.742Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-07T00:16:38.833

Modified: 2026-08-07T19:01:11.610

Link: CVE-2026-65668

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T01:45:05Z

Weaknesses