Vulnerability Brief

CVE-2026-48582

  • Severity: CRITICAL
  • CVSS score: 9.6

Technical summary

Missing authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network.