CVE-2026-70178: Microsoft Fabric Elevation of Privilege Vulnerability
Microsoft Fabric Elevation of Privilege Vulnerability
Other sources
Missing authorization in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.
— Microsoft
Affected Software
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An attacker must already be authorized to access Microsoft Fabric and be able to reach it over the network. The available information does not indicate that unauthenticated attackers can exploit it.
What is the likely impact if exploitation succeeds?
A successful attacker can elevate privileges. The assigned vector indicates potential high impact to confidentiality, integrity, and availability, with impacts extending beyond the initially affected security authority.
Does exploitation require user interaction or a simple attack path?
No user interaction is required. However, the attack complexity is rated high, indicating exploitation requires conditions or circumstances beyond routine authenticated access.