Description
Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
Published: 2026-09-08
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Patch
AI Analysis

Impact

An attacker who already possesses valid Exchange Server credentials can exploit a missing authorization check to increase their privileges. Because the flaw does not require external network exposure, the attack can be executed from any internal or compromised network node that can reach the Exchange instance. The effect of the weak check is an elevation of privilege that could enable the attacker to run arbitrary commands, read confidential data, or tamper with server configuration, thereby compromising confidentiality, integrity, and availability of the Exchange environment.

Affected Systems

The vulnerability affects Microsoft Exchange Server 2016 Cumulative Update 23, Microsoft Exchange Server 2019 Cumulative Update 14, Microsoft Exchange Server 2019 Cumulative Update 15, and Microsoft Exchange Server Subscription Edition RTM. Each affected release has a known missing authorization guard that can be triggered with existing authenticated privileges.

Risk and Exploitability

The CVSS score of 8.1 indicates a high severity threat. The EPSS score is not available, and the vulnerability is not listed in CISA Kev. Attackers need legitimate credentials but do not require higher privileges or special network access; the exploit can be performed within a normal network segment where the Exchange Server is reachable, implying a moderate to high likelihood of exploitation once credentials are compromised. The vulnerability is therefore considered a significant risk to organizations with unpatched Exchange installations.

Generated by OpenCVE AI on September 8, 2026 at 21:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Microsoft Exchange Server 2016 Cumulative Update 23 patch to secure the 2016 environment.
  • Apply the Microsoft Exchange Server 2019 Cumulative Update 15 patch (or upgrade to a later update) to fix the 2019 installations.
  • If immediate patching is not possible, restrict the privileges of all Exchange users to the least privilege required for their roles and monitor for unauthorized privilege escalation attempts.

Generated by OpenCVE AI on September 8, 2026 at 21:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
Title Microsoft Exchange Server Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft exchange Server 2016
Microsoft exchange Server 2019
Microsoft exchange Server Se
Weaknesses CWE-862
CPEs cpe:2.3:a:microsoft:exchange_server_2016:*:cumulative_update_23:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server_2019:*:cumulative_update_14:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server_2019:*:cumulative_update_15:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server_se:*:RTM:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft exchange Server 2016
Microsoft exchange Server 2019
Microsoft exchange Server Se
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Exchange Server 2016 Exchange Server 2019 Exchange Server Se
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:32:44.052Z

Reserved: 2026-08-03T20:54:04.487Z

Link: CVE-2026-69380

cve-icon Vulnrichment

Updated: 2026-09-09T10:01:44.915Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T18:18:58.803

Modified: 2026-09-09T10:18:18.427

Link: CVE-2026-69380

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T04:30:04Z

Weaknesses