CVE-2026-69641: Microsoft Exchange Server Elevation of Privilege Vulnerability
Microsoft Exchange Server Elevation of Privilege Vulnerability
Other sources
Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.02.2562.049Patch KB5121608 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.02.1748.051Patch KB5121609 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.01.2507.073Patch KB5121611 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.02.1544.046Patch KB5121610
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An attacker must already be authorized to access the affected Microsoft Exchange Server and be able to reach it over the network. The available data does not indicate that unauthenticated attackers can exploit it.
Which Exchange Server releases are identified as affected?
Microsoft Exchange Server 2016, Microsoft Exchange Server 2019, and Microsoft Exchange Server Subscription Edition RTM are listed.
What level of impact could successful exploitation have?
Successful exploitation can allow an authorized attacker to elevate privileges. The supplied severity vector indicates high potential impact to confidentiality, integrity, and availability, with scope changed.