Insufficient Granularity of Access Control in Microsoft Exchange Server - CVE-2026-55006
Published: July 16, 2026
Vulnerability identifier: #VU137891
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-55006
CWE-ID: CWE-1220
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to insufficient granularity of access control in Microsoft Exchange Server, which leads to security restrictions bypass and privilege escalation.
Affected software
Microsoft Exchange Server
How to mitigate CVE-2026-55006
Install updates from vendor's website.
Microsoft Exchange Server - addressed in versions SE RTM Jul26SU 15.02.2562.045, 2016 CU23 Jul26SU 15.01.2507.071, 2019 CU14 Jul26SU 15.02.1544.043, 2019 CU15 Jul26SU 15.02.1748.048