Impact
Missing authorization controls within Microsoft Fabric allow an attacker who already holds authorizations over a network to gain higher privileges. The flaw is assigned CWE-862, indicating a missing or improper access control. Once exploited, an attacker could elevate privileges and potentially access or modify data and resources beyond their intended scope, compromising confidentiality, integrity, or availability.
Affected Systems
Microsoft Fabric is affected by this vulnerability. No specific version information was provided in the advisory, so all current deployments of Microsoft Fabric should be considered at risk.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.5, classifying it as high severity. The EPSS score is currently not available, and it is not listed in the CISA KEV catalog, indicating a lower known exploitation likelihood as of now. The likely attack vector requires an authorized attacker with network access and permissions to send requests to Microsoft Fabric services, after which the missing authorization allows privilege escalation.
OpenCVE Enrichment