Impact
An authorization bypass occurs when an attacker manipulates a user-controlled key in Microsoft Partner Center, enabling the attacker to read protected information over the network. The flaw is classified as CWE‑639, representing an unauthorized retrieval of data due to insufficient validation of user-supplied input. The impact is a breach of confidentiality, as sensitive partner data can be accessed without proper authorization, though no direct denial of service or execution of code is described in the announcement.
Affected Systems
The affected product is Microsoft Partner Center, as identified by the CNA. No specific version numbers are listed, so all current versions deployed in an environment could potentially be impacted until a vendor patch is issued.
Risk and Exploitability
The CVSS score of 8.6 indicates a high severity level. The EPSS score is not available, so the current exploitation likelihood is uncertain. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a network-based approach where an attacker submits a crafted key parameter to the Partner Center API or web interface. No privileged access or local code execution is required, but a legitimate user context can be leveraged to bypass authorization checks.
OpenCVE Enrichment