Improper Control of Resource Identifiers ('Resource Injection') in Microsoft Exchange Server - CVE-2026-62910
Published: August 11, 2026
Vulnerability details
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to improper control of resource identifiers ('resource injection') in Microsoft Exchange Server when handling network requests. A remote privileged user can send crafted requests to escalate privileges.
Successful exploitation could result in SYSTEM privileges.