Impact
Microsoft Fabric contains an authentication bypass flaw that enables an attacker to impersonate a valid credential and gain higher privileges on the network. The vulnerability exists through spoofing of authentication tokens, which allows unrestricted actions beyond the intended user scope. This flaw can lead to complete control over Fabric resources and data if exploited.
Affected Systems
Microsoft Fabric is the affected product. No specific version numbers are provided, so all deployed instances should be considered vulnerable until a patch is applied.
Risk and Exploitability
The flaw carries a CVSS score of 10, indicating the highest impact and difficulty for mitigation. The EPSS score is less than 1%, suggesting low probability of current exploitation but not impossible. The vulnerability is not listed in the CISA KEV catalog. Attack is likely to be carried out over the network through spoofed authentication traffic, requiring no local access or elevated rights prior to exploitation.
OpenCVE Enrichment