CVE-2026-45504

Published Jun 9, 2026

Last updated 5 days ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-45504 is identified as a Server-Side Request Forgery (SSRF) vulnerability affecting Microsoft Exchange Server. This flaw, categorized under CWE-918, enables an authenticated attacker to elevate privileges across a network. The vulnerability resides in Exchange Server's request-handling logic, which processes attacker-controlled URLs without adequate validation, allowing the server to initiate requests to internal resources on behalf of the attacker. Exploitation of CVE-2026-45504 can allow an authenticated user with low privileges to submit crafted requests, causing the Exchange server to make outbound or internal HTTP calls. These requests inherit the trust of the Exchange service account, potentially granting the attacker access to resources that would otherwise be inaccessible from their session. In some instances, this SSRF can be leveraged to read arbitrary local files from the Exchange server. This vulnerability was disclosed as part of Microsoft's June 2026 Patch Tuesday release.

Description
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
Source
secure@microsoft.com
NVD status
Analyzed
Products
exchange_server, exchange_server_subscription_edition

Risk scores

CVSS 3.1

Type
Secondary
Base score
8.8
Impact score
5.9
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

secure@microsoft.com
CWE-918

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.