CVSS 8.6 · HIGH
CVE-2026-26150
Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network.
View on NVDAnalysis
Microsoft Purview eDiscovery contains a server-side request forgery (SSRF) vulnerability that allows unauthorized attackers to elevate their privileges over the network. Organizations using Purview for data governance and legal discovery should verify their security updates to prevent unauthorized access to sensitive compliance records.
Severity
Score: 8.6(HIGH)
Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:NAV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: CHANGED
C: HIGH
I: NONE
A: NONE
Weakness (CWE):
CWE-918EPSS
Probability of exploitation (next 30 days): 0.0009 (0.1%)
Percentile: 25.2%
EPSS: 2026-05-06
Affects
microsoft:purview_ediscoveryTechnical description
Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network.
Published: 4/23/2026, 10:16:23 PM
Last modified: 4/29/2026, 7:10:35 PM