Missing Authorization in Microsoft Exchange Server - CVE-2026-69641
Published: September 8, 2026
Vulnerability details
The vulnerability allows a remote user to access or modify other users\' mailbox content.
The vulnerability exists due to missing authorization in Microsoft Exchange Server when processing specially crafted network requests. A remote privileged user can send a specially crafted request to bypass mailbox authorization checks and access or modify other users\' mailbox content.
No user interaction is required.