SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-15630

CRITICAL · CVSS 9.9 EPSS 0.25% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-23 · Last synced 2026-08-22

CyberRota Analysis

AI-Generated

A vulnerability exists that allows a non-global organization admin within one tenant to bypass tenant boundaries, enabling unauthorized deletion, creation, or modification of resources across other tenants due to a flaw in the authorization mechanism. This critical issue poses significant risks to multi-tenant environments, potentially leading to data breaches and resource manipulation. Organizations utilizing multi-tenant architectures should prioritize remediation to safeguard against potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-15630
Severity
CRITICAL
CVSS
9.9
EPSS
0.25%

Original NVD Description

A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in any other tenant by exploiting a mismatch between authorization (based on ?id=) and action (based on request body).