SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-49159

MEDIUM · CVSS 6.5 EPSS 0.55%

Source: NVD + CISA KEV + EPSS · Published 2026-07-24 · Last synced 2026-08-23

CyberRota Analysis

AI-Generated

Microsoft Graph is vulnerable to unauthorized information disclosure, allowing an attacker with valid credentials to access sensitive data over the network. This could lead to significant privacy breaches and data leaks. Organizations using Microsoft Graph should prioritize addressing this vulnerability to protect their sensitive information from potential exploitation.

CVE
CVE-2026-49159
Severity
MEDIUM
CVSS
6.5
EPSS
0.55%
Microsoft

Original NVD Description

Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network.

Related CVEs

Other vulnerabilities affecting the same vendor(s)