AI description
Automated description summarized from trusted sources.
CVE-2026-62835 is an information disclosure vulnerability affecting Online Services, including the Azure Portal, stemming from improper authorization. This flaw allows unauthorized attackers to disclose sensitive information across a network. The vulnerability is rooted in inadequate validation of user permissions and session management mechanisms within the authorization process. Attackers can exploit this weakness to bypass legitimate access controls and retrieve data that should otherwise be restricted, often through insufficient input validation in API endpoints or web interfaces.
- Description
- Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network.
- Source
- secure@microsoft.com
- NVD status
- Awaiting Analysis
- CNA Tags
- exclusively-hosted-service
CVSS 3.1
- Type
- Primary
- Base score
- 9.3
- Impact score
- 4.7
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L
- Severity
- CRITICAL
- secure@microsoft.com
- CWE-285
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
9