CVE-2026-42826: Azure DevOps Information Disclosure Vulnerability
Published May 7, 2026
·Updated
Azure DevOps Information Disclosure Vulnerability
Other sources
Exposure of sensitive information to an unauthorized actor in Azure DevOps allows an unauthorized attacker to disclose information over a network.
— Microsoft
Affected Software
2 affected components
Microsoft Azure DevOps
Microsoft Azure DevOps
Event History
May 7, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·02:00 PM
Description
CVE Published
via MITRE·08:59 PM
Data Sourced
via MITRE·08:59 PM
DescriptionSeverity
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-42826?
CVE-2026-42826 is considered to have a moderate severity rating due to the potential for unauthorized information disclosure.
2
How do I fix CVE-2026-42826?
To fix CVE-2026-42826, update your Azure DevOps installation to the latest version provided by Microsoft.
3
What information can be disclosed in CVE-2026-42826?
CVE-2026-42826 allows unauthorized actors to potentially access sensitive information over a network.
4
Who is affected by CVE-2026-42826?
CVE-2026-42826 affects users and organizations utilizing Microsoft Azure DevOps.
5
Is CVE-2026-42826 being actively exploited?
There are currently no reports confirming active exploitation of CVE-2026-42826 in the wild.