← Back

CVE-2026-26118

nvd nist
Published: Mar 10, 2026Modified: Mar 13, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: secure@microsoft.com

Description

Server-side request forgery (ssrf) in Azure MCP Server allows an authorized attacker to elevate privileges over a network.

Affected (17)

1 product
Azure Mcp Server
Configuration A
17 vulnerable
Vulnerable SoftwareAffected Versions
Microsoft
Before 2.0.0
Version 2.0.0 beta10
Version 2.0.0 beta11
Version 2.0.0 beta12
Version 2.0.0 beta13
Version 2.0.0 beta14
Version 2.0.0 beta15
Version 2.0.0 beta16
Version 2.0.0 beta1
Version 2.0.0 beta2
Version 2.0.0 beta3
Version 2.0.0 beta4
Version 2.0.0 beta5
Version 2.0.0 beta6
Version 2.0.0 beta7
Version 2.0.0 beta8
Version 2.0.0 beta9

References (1)

Timeline

No history available yet.