CVE-2026-62835

Published Jul 24, 2026

Last updated 4 hours ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-62835 is an information disclosure vulnerability affecting Online Services, including the Azure Portal, stemming from improper authorization. This flaw allows unauthorized attackers to disclose sensitive information across a network. The vulnerability is rooted in inadequate validation of user permissions and session management mechanisms within the authorization process. Attackers can exploit this weakness to bypass legitimate access controls and retrieve data that should otherwise be restricted, often through insufficient input validation in API endpoints or web interfaces.

Description
Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network.
Source
secure@microsoft.com
NVD status
Awaiting Analysis
CNA Tags
exclusively-hosted-service

Risk scores

CVSS 3.1

Type
Primary
Base score
9.3
Impact score
4.7
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L
Severity
CRITICAL

Weaknesses

secure@microsoft.com
CWE-285

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

9

References

Sources include official advisories and independent security research.