Description
Authorization bypass through user-controlled key in Microsoft Partner Center allows an unauthorized attacker to disclose information over a network.
Published: 2026-08-20
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An authorization bypass occurs when an attacker manipulates a user-controlled key in Microsoft Partner Center, enabling the attacker to read protected information over the network. The flaw is classified as CWE‑639, representing an unauthorized retrieval of data due to insufficient validation of user-supplied input. The impact is a breach of confidentiality, as sensitive partner data can be accessed without proper authorization, though no direct denial of service or execution of code is described in the announcement.

Affected Systems

The affected product is Microsoft Partner Center, as identified by the CNA. No specific version numbers are listed, so all current versions deployed in an environment could potentially be impacted until a vendor patch is issued.

Risk and Exploitability

The CVSS score of 8.6 indicates a high severity level. The EPSS score is not available, so the current exploitation likelihood is uncertain. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a network-based approach where an attacker submits a crafted key parameter to the Partner Center API or web interface. No privileged access or local code execution is required, but a legitimate user context can be leveraged to bypass authorization checks.

Generated by OpenCVE AI on August 21, 2026 at 00:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check for and install any Microsoft Partner Center updates that address CVE-2026-69558 as soon as they become available.
  • Restrict Partner Center access to verified, authorized users and enforce multi‑factor authentication to minimize the risk of unauthorized key manipulation.
  • Audit and monitor incoming requests for unusual or malformed key parameters, and log any authorization failures for further investigation.

Generated by OpenCVE AI on August 21, 2026 at 00:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:microsoft:partner_center:-:*:*:*:*:*:*:*

Fri, 21 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Description Authorization bypass through user-controlled key in Microsoft Partner Center allows an unauthorized attacker to disclose information over a network.
Title Microsoft Partner Center Information Disclosure Vulnerability
First Time appeared Microsoft
Microsoft partner Center
Weaknesses CWE-639
CPEs cpe:2.3:a:microsoft:partner_center:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft partner Center
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Partner Center
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-09T19:38:38.369Z

Reserved: 2026-08-03T21:15:56.835Z

Link: CVE-2026-69558

cve-icon Vulnrichment

Updated: 2026-08-21T15:32:22.913Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-20T22:18:00.610

Modified: 2026-08-25T16:08:48.697

Link: CVE-2026-69558

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T01:15:06Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key