CVE-2026-55006: Microsoft Exchange Server Elevation of Privilege Vulnerability
Insufficient granularity of access control in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.
Other sources
Microsoft Exchange Server Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.02.1748.048Patch KB5103213 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.01.2507.071Patch KB5103215 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.02.1544.043Patch KB5103214 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.02.2562.045Patch KB5103212
Event History
Frequently Asked Questions
What is the severity of CVE-2026-55006?
CVE-2026-55006 has a high severity score of 7.8.
How do I fix CVE-2026-55006?
To fix CVE-2026-55006, apply the latest security update provided by Microsoft for your version of Exchange Server.
What type of attack does CVE-2026-55006 facilitate?
CVE-2026-55006 allows an authorized attacker to elevate privileges locally within Microsoft Exchange Server.
Which versions of Microsoft Exchange Server are affected by CVE-2026-55006?
CVE-2026-55006 affects Microsoft Exchange Server 2019, 2016, and Subscription Edition RTM.
What is the risk associated with CVE-2026-55006?
CVE-2026-55006 has a risk level of 69, indicating a significant threat to system security.