CVE-2026-48567

Published Jun 4, 2026

Last updated a day ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-48567 is an authentication bypass vulnerability affecting Azure HorizonDB, Microsoft's preview PostgreSQL-compatible database service. Disclosed by Microsoft on June 4, 2026, this flaw allows an unauthorized attacker to bypass authentication through spoofing. Successful exploitation of CVE-2026-48567 enables an attacker to elevate privileges over a network, potentially leading to modifications in system integrity and disruption of service availability within Azure HorizonDB.

Description
Authentication bypass by spoofing in Azure HorizonDB allows an unauthorized attacker to elevate privileges over a network.
Source
secure@microsoft.com
NVD status
Analyzed
CNA Tags
exclusively-hosted-service
Products
azure_horizondb

Risk scores

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

secure@microsoft.com
CWE-290

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

2

Configurations

References

Sources include official advisories and independent security research.