← Back to CVE List
CVE-2026-69641NVD
Vulnerability Summary
Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
CVSS v3.1 Base Metrics — Score 9.1 (CRITICAL)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredHigh
User InteractionNone
ScopeChanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh
Affected & Patched Versions
- Microsoft Exchange Server
- Microsoft Exchange Server Subscription Edition < 15.02.2562.049
- Microsoft Exchange Server Subscription Edition 15.02.2562.049