Skip to content
CVSS 10.0CVSS 10.0 · CRITICAL

CVE-2026-42826

Exposure of sensitive information to an unauthorized actor in Azure DevOps allows an unauthorized attacker to disclose information over a network.

View on NVD

Analysis

A critical vulnerability in Azure DevOps (CVSS 10.0) allows unauthorized network actors to access sensitive information. This could potentially lead to the exposure of private source code, environment secrets, or internal development data.

Severity

Score: 10.0(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: CHANGED
C: HIGH
I: HIGH
A: HIGH
Weakness (CWE): CWE-200

EPSS

No EPSS score yet (CVE may be too fresh).

Technical description

Exposure of sensitive information to an unauthorized actor in Azure DevOps allows an unauthorized attacker to disclose information over a network.

Published: 5/7/2026, 10:16:35 PM
Last modified: 5/7/2026, 10:16:35 PM

References

HomeEventsBlogResourcesTeam