Sceawere
Vulnerability Detail
CVE-2026-65668UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Microsoft Purview eDiscovery Privilege Escalation
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.8
- Creation Date
- 1d ago
- Vendor
- Microsoft
- Product
- Microsoft Purview eDiscovery
- Attack Type
- CWE-284: Improper Access Control
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Improper access control in Microsoft Purview eDiscovery allows an authorized attacker to elevate privileges over a network.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.8",
"pubDate": "2026-08-07T00:16:38.833Z",
"pubdate": "2026-08-07T00:16:38.833Z",
"executiveSummary": "An improper access control vulnerability has been identified within Microsoft Purview eDiscovery. This security flaw permits an authenticated attacker to execute unauthorized privilege escalation over a network vector. The vulnerability directly impacts the security posture of the affected enterprise messaging and compliance ecosystems, introducing significant risk regarding unauthorized access to sensitive legal and investigative data.\nThe primary impact of this vulnerability involves unauthorized elevation of privileges, potentially granting malicious actors administrative or elevated capabilities within the eDiscovery framework. Exploitation of this security defect requires network connectivity to the target environment and assumes the attacker possesses an initial level of authorization to interact with the service. By leveraging improper access controls, an authenticated user can bypass boundary enforcement mechanisms designed to restrict administrative functions and data discovery tools.\nGiven the nature of eDiscovery systems, which frequently index and store highly sensitive enterprise communications, successful exploitation could lead to severe confidentiality breaches, unauthorized data tampering, or full administrative compromise of the affected compliance domain. Organizations deploying Microsoft Purview eDiscovery are exposed to these heightened risks until appropriate vendor-supplied patches or administrative workarounds are fully deployed.",
"technicalDetails": "The root cause of this vulnerability stems from improper access control enforcement within the authorization logic of Microsoft Purview eDiscovery. The application fails to adequately validate whether an authenticated user possesses the requisite administrative context or security roles before granting access to privileged application functions. Consequently, authorization boundaries that should logically segment standard users from administrative operators can be circumvented.\nExploitation of this vulnerability occurs over a network vector, requiring the attacker to interact with the affected service endpoints associated with Microsoft Purview eDiscovery. Because the attacker must already be authenticated to the system, this vulnerability represents a post-auth privilege escalation vector (often aligned with vertical privilege escalation patterns). The attack flow generally initiates with the attacker issuing specially crafted requests or API calls directed at administrative interfaces or management modules that lack proper back-end validation checks.\nUpon receiving the request, the vulnerable component processes the command without verifying the caller's contextual permissions against the requested resource or administrative action. This allows the payload or operational command to execute with elevated privileges, bypassing the intended role-based access control (RBAC) restrictions. The vulnerable component fails to enforce principle of least privilege principles during transaction handling, leading to unauthorized state changes or access grants within the eDiscovery service architecture.\nPost-exploitation impact associated with this flaw includes the potential acquisition of administrative privileges, unauthorized retrieval of sequestered eDiscovery cases, modification of legal hold configurations, and potential operational disruption of compliance monitoring tools. Remediation requires strict enforcement of server-side authorization checks and comprehensive validation of security context tokens for all administrative API requests."
}