Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2026-62915

Опубликовано: 11 авг. 2026
Источник: msrc
CVSS3: 6.5
EPSS Низкий

Описание

Microsoft Exchange Server Security Feature Bypass Vulnerability

Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network.

FAQ

What kind of security feature could be bypassed by successfully exploiting this vulnerability?

An authenticated attacker who successfully exploited this vulnerability could bypass a role-based restriction that is intended to control which users are allowed to install mail add-ins. By bypassing this control, a user could install an add-in that requests elevated mailbox permissions that an administrator's policy was meant to prevent.

Обновления

ПродуктСтатьяОбновление
Microsoft Exchange Server 2016 Cumulative Update 23
-
Microsoft Exchange Server 2019 Cumulative Update 14
-
Microsoft Exchange Server 2019 Cumulative Update 15
-
Microsoft Exchange Server Subscription Edition RTM

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Less Likely

EPSS

Процентиль: 40%
0.00494
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
2 дня назад

Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network.

CVSS3: 6.5
github
2 дня назад

Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network.

EPSS

Процентиль: 40%
0.00494
Низкий

6.5 Medium

CVSS3