CVE-2026-69558
Received Received - Intake

Authorization Bypass in Microsoft Partner Center

Vulnerability report for CVE-2026-69558, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-20

Last updated on: 2026-08-20

Assigner: Microsoft Corporation

Description

Authorization bypass through user-controlled key in Microsoft Partner Center allows an unauthorized attacker to disclose information over a network.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-20
Last Modified
2026-08-20
Generated
2026-08-21
AI Q&A
2026-08-21
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
microsoft partner_center *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an authorization bypass in Microsoft Partner Center. It allows an unauthorized attacker to bypass normal access controls and disclose sensitive information over a network by manipulating a user-controlled key.

Detection Guidance

This vulnerability involves authorization bypass through user-controlled keys in Microsoft Partner Center. Detection requires monitoring for unauthorized access attempts or unusual API calls to Microsoft Partner Center endpoints. Check logs for requests with manipulated keys or unexpected data exposure patterns. No specific commands are provided in the context.

Impact Analysis

An attacker could exploit this to access confidential data, such as customer or business information, without proper authorization. This could lead to data leaks, privacy violations, or unauthorized actions within the Partner Center environment.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR, HIPAA, or other regulations by enabling unauthorized access to protected data. Organizations may face legal penalties, reputational damage, and loss of trust due to data breaches resulting from this issue.

Mitigation Strategies

Apply Microsoft Partner Center security updates immediately. Review and restrict access controls to prevent unauthorized access. Monitor network traffic for unusual activity related to Partner Center services.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-69558. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart