Description
Authentication bypass by spoofing in Microsoft Fabric allows an unauthorized attacker to elevate privileges over a network.
Published: 2026-09-17
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Apply Patch
AI Analysis

Impact

Microsoft Fabric contains an authentication bypass flaw that enables an attacker to impersonate a valid credential and gain higher privileges on the network. The vulnerability exists through spoofing of authentication tokens, which allows unrestricted actions beyond the intended user scope. This flaw can lead to complete control over Fabric resources and data if exploited.

Affected Systems

Microsoft Fabric is the affected product. No specific version numbers are provided, so all deployed instances should be considered vulnerable until a patch is applied.

Risk and Exploitability

The flaw carries a CVSS score of 10, indicating the highest impact and difficulty for mitigation. The EPSS score is less than 1%, suggesting low probability of current exploitation but not impossible. The vulnerability is not listed in the CISA KEV catalog. Attack is likely to be carried out over the network through spoofed authentication traffic, requiring no local access or elevated rights prior to exploitation.

Generated by OpenCVE AI on September 18, 2026 at 23:00 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Microsoft Fabric update from the Microsoft Security Response Center.
  • Restrict inbound network traffic to Fabric services to only trusted hosts or subnets.
  • Implement network segmentation and monitoring to detect authentication spoofing attempts.

Generated by OpenCVE AI on September 18, 2026 at 23:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 25 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:microsoft:fabric:-:*:*:*:*:*:*:*

Sat, 19 Sep 2026 05:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft fabric
Vendors & Products Microsoft fabric

Thu, 17 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Description Authentication bypass by spoofing in Microsoft Fabric allows an unauthorized attacker to elevate privileges over a network.
Title Microsoft Fabric Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft microsoft Fabric
Weaknesses CWE-290
CPEs cpe:2.3:a:microsoft:microsoft_fabric:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft microsoft Fabric
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Fabric Microsoft Fabric
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-10-08T18:20:39.392Z

Reserved: 2026-08-03T22:51:46.190Z

Link: CVE-2026-69843

cve-icon Vulnrichment

Updated: 2026-09-18T14:30:42.884Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-18T00:17:24.923

Modified: 2026-09-25T19:53:30.793

Link: CVE-2026-69843

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T23:15:17Z

Weaknesses
  • CWE-290

    Authentication Bypass by Spoofing