Description
Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network.
Published: 2026-10-02
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: Elevation of Privilege
Action: Apply Patch
AI Analysis

Impact

A weakness in the authorization logic of Microsoft Exchange Server can allow an attacker that has authenticated network access to gain higher privileges than intended. The flaw is recognized as CWE-1390 and could enable the attacker to perform actions as a system administrator or other privileged user, compromising confidentiality, integrity, and availability of mail services.

Affected Systems

Microsoft Exchange Server 2016 Cumulative Update 23, Microsoft Exchange Server 2019 Cumulative Update 14, Microsoft Exchange Server 2019 Cumulative Update 15, Microsoft Exchange Server Subscription Edition RTM are affected. Users of these versions should verify which cumulative update applies to their installation.

Risk and Exploitability

The CVSS base score of 8.8 indicates a high impact risk, and the EPSS score is unavailable, suggesting limited publicly known exploitation data. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector requires the attacker to be authenticated on the network, then exploit the weak authorization check to elevate privileges. No further conditions appear to be required.

Generated by OpenCVE AI on October 2, 2026 at 20:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Microsoft Exchange Server to the latest cumulative updates (CU23 for 2016, CU14/CU15 for 2019, and the most recent RTM for the Subscription edition).
  • Restrict privileged account use by enforcing least‑privilege policies and monitoring authentication events.
  • Conduct a security audit of role assignments and enforce full separation of duties to detect potential abuse of elevated privileges.

Generated by OpenCVE AI on October 2, 2026 at 20:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 02 Oct 2026 19:15:00 +0000

Type Values Removed Values Added
Description Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network.
Title Microsoft Exchange Server Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft exchange Server 2016
Microsoft exchange Server 2019
Microsoft exchange Server Se
Weaknesses CWE-1390
CPEs cpe:2.3:a:microsoft:exchange_server_2016:*:cumulative_update_23:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server_2019:*:cumulative_update_14:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server_2019:*:cumulative_update_15:*:*:*:*:*:*
cpe:2.3:a:microsoft:exchange_server_se:*:RTM:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft exchange Server 2016
Microsoft exchange Server 2019
Microsoft exchange Server Se
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Exchange Server 2016 Exchange Server 2019 Exchange Server Se
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-10-02T20:14:51.320Z

Reserved: 2026-09-23T20:35:19.927Z

Link: CVE-2026-96940

cve-icon Vulnrichment

Updated: 2026-10-02T20:14:47.451Z

cve-icon NVD

Status : Received

Published: 2026-10-02T19:16:43.023

Modified: 2026-10-02T21:16:58.060

Link: CVE-2026-96940

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T20:30:16Z

Weaknesses