CVE-2026-96207

Published Oct 8, 2026

Last updated 3 hours ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-96207 is an elevation of privilege vulnerability affecting Microsoft Partner Center, a platform used by enterprises to manage cloud services, licenses, and customer accounts. The vulnerability stems from improper certificate validation mechanisms within the platform. This flaw allows an unauthorized attacker to exploit the validation process over a network, enabling them to elevate their privileges within the Microsoft Partner Center environment. Successful exploitation of this vulnerability can lead to unauthorized access and control over affected systems within the network. Microsoft has addressed the issue by incorporating it into its security update guidance. To mitigate potential exploitation risks, organizations are advised to apply the official patches provided by Microsoft and review their access controls.

Description
Improper certificate validation in Microsoft Partner Center allows an unauthorized attacker to elevate privileges over a network.
Source
secure@microsoft.com
NVD status
Awaiting Analysis
CNA Tags
exclusively-hosted-service

Risk scores

CVSS 3.1

Type
Secondary
Base score
10
Impact score
5.8
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Severity
CRITICAL

Weaknesses

secure@microsoft.com
CWE-295

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

10

References

Sources include official advisories and independent security research.