CVE-2026-94510: Microsoft Bookings Elevation of Privilege Vulnerability
Published Oct 8, 2026
·Updated
Authorization bypass through user-controlled key in Microsoft Bookings allows an unauthorized attacker to elevate privileges over a network.
Other sources
Microsoft Bookings Elevation of Privilege Vulnerability
— Microsoft
Affected Software
2 affected components
Microsoft Bookings
Microsoft Bookings
Event History
Oct 8, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeaknessAffected Software
CVE Published
via MITRE·10:15 PM
Data Sourced
via MITRE·10:15 PM
DescriptionSeverity
Data Sourced
via NVD·11:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this vulnerability?
An unauthorized attacker can exploit it over a network. No privileges or user interaction are required according to the supplied severity vector.
2
What is the likely security impact?
Successful exploitation allows elevation of privilege through an authorization bypass involving a user-controlled key. The supplied vector indicates high integrity impact, low confidentiality impact, and low availability impact, with scope changed.
3
Is there a workaround or mitigation if patching cannot happen immediately?
No workaround, mitigation, affected configuration details, or remediation information is provided in the available data.