Description
Authorization bypass through user-controlled key in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network.
Published: 2026-09-08
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authorization bypass enabling unauthorized tampering via network by authorized user.
Action: Patch
AI Analysis

Impact

The vulnerability is an authorization bypass that allows an attacker with legitimate credentials to supply a user-controlled key and alter configuration or data on a Microsoft Exchange Server. This flaw, classified as CWE-639, enables tampering of system settings and potentially sensitive information without proper authorization.

Affected Systems

Affected systems include Microsoft Exchange Server 2016 updated to Cumulative Update 23, Microsoft Exchange Server 2019 updated to Cumulative Update 14 or 15, and Microsoft Exchange Server Subscription Edition Release to Market. Administrators should check these specific builds for the vulnerability.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires the attacker to be authenticated on the network; they can then manipulate the key to bypass authorization and perform tampering actions. Because of the network exposure, defenders should treat this as a potential privileged abuse scenario.

Generated by OpenCVE AI on September 8, 2026 at 21:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Microsoft Exchange Server cumulative updates that contain the patch for CVE-2026-69375.
  • Review and secure key management settings to prevent user-controlled keys from bypassing authorization.
  • Monitor Exchange logs for evidence of unauthorized tampering and enforce least privilege access controls.

Generated by OpenCVE AI on September 8, 2026 at 21:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Authorization bypass through user-controlled key in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network.
Title Microsoft Exchange Server Tampering Vulnerability
First Time appeared Microsoft
Microsoft exchange Server 2016
Microsoft exchange Server 2019
Microsoft exchange Server Se
Weaknesses CWE-639
CPEs cpe:2.3:a:microsoft:exchange_server_2016:*:cumulative_update_23:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server_2019:*:cumulative_update_14:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server_2019:*:cumulative_update_15:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server_se:*:RTM:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft exchange Server 2016
Microsoft exchange Server 2019
Microsoft exchange Server Se
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Exchange Server 2016 Exchange Server 2019 Exchange Server Se
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:32:43.068Z

Reserved: 2026-08-03T20:54:04.486Z

Link: CVE-2026-69375

cve-icon Vulnrichment

Updated: 2026-09-11T14:51:09.227Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T18:18:58.057

Modified: 2026-09-11T15:17:02.730

Link: CVE-2026-69375

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T03:45:03Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key