CVSS 10.0CVSS 10.0 · CRITICAL
CVE-2026-42826
Exposure of sensitive information to an unauthorized actor in Azure DevOps allows an unauthorized attacker to disclose information over a network.
View on NVDAnalysis
A critical vulnerability in Azure DevOps (CVSS 10.0) allows unauthorized network actors to access sensitive information. This could potentially lead to the exposure of private source code, environment secrets, or internal development data.
Severity
Score: 10.0(CRITICAL)
Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HAV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: CHANGED
C: HIGH
I: HIGH
A: HIGH
Weakness (CWE):
CWE-200EPSS
No EPSS score yet (CVE may be too fresh).
Technical description
Exposure of sensitive information to an unauthorized actor in Azure DevOps allows an unauthorized attacker to disclose information over a network.
Published: 5/7/2026, 10:16:35 PM
Last modified: 5/7/2026, 10:16:35 PM