Skip to content
CVSS 8.6 · HIGH

CVE-2026-26150

Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network.

View on NVD

Analysis

Microsoft Purview eDiscovery contains a server-side request forgery (SSRF) vulnerability that allows unauthorized attackers to elevate their privileges over the network. Organizations using Purview for data governance and legal discovery should verify their security updates to prevent unauthorized access to sensitive compliance records.

Severity

Score: 8.6(HIGH)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: CHANGED
C: HIGH
I: NONE
A: NONE
Weakness (CWE): CWE-918

EPSS

Probability of exploitation (next 30 days): 0.0009 (0.1%)
Percentile: 25.2%
EPSS: 2026-05-06

Affects

microsoft:purview_ediscovery

Technical description

Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network.

Published: 4/23/2026, 10:16:23 PM
Last modified: 4/29/2026, 7:10:35 PM

References

HomeEventsBlogResourcesTeam