Missing Authorization in Microsoft Exchange Server - CVE-2026-62915
Published: August 11, 2026
Vulnerability details
The vulnerability allows a remote user to bypass a security feature.
The vulnerability exists due to missing authorization in Microsoft Exchange Server when handling requests to install mail add-ins. A remote user can send a crafted request to bypass a role-based restriction intended to control which users are allowed to install mail add-ins.
A successful exploit could allow installation of an add-in that requests elevated mailbox permissions that an administrator's policy was intended to prevent.