CVE-2026-62835

Published Jul 24, 2026

Last updated a month ago

CVSS critical 9.3
Server
Azure Portal

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-62835 is an information disclosure vulnerability affecting Online Services, including the Azure Portal, stemming from improper authorization. This flaw allows unauthorized attackers to disclose sensitive information across a network. The vulnerability is rooted in inadequate validation of user permissions and session management mechanisms within the authorization process. Attackers can exploit this weakness to bypass legitimate access controls and retrieve data that should otherwise be restricted, often through insufficient input validation in API endpoints or web interfaces.

Description
Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network.
Source
secure@microsoft.com
NVD status
Analyzed
CNA Tags
exclusively-hosted-service
Products
azure_portal

Risk scores

CVSS 3.1

Type
Primary
Base score
7.5
Impact score
3.6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Severity
HIGH

Weaknesses

secure@microsoft.com
CWE-285

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.