CVE-2026-26138 is a critical server-side request forgery (SSRF) vulnerability in Microsoft Purview that allows an unauthorized attacker to elevate privileges over a network. Rated with a CVSS score of 10.0, this flaw requires no user interaction or prior privileges, enabling a complete compromise of confidentiality, integrity, and availability. Despite its maximum severity, there is currently no evidence of active exploitation, nor are public exploit codes or community discussions available. The vulnerability is not listed on CISA's KEV catalog and has a very low EPSS score, indicating a low probability of exploitation in the wild.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:purview:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.