CVE-2026-62910
Improper control of resource identifiers ('resource injection') in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.2
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
- EPSS probability
- 0.68%
- CWE
- CWE-99
- Published
- 2026-08-11
- Last modified
- 2026-09-09
Affected products
- Microsoft Microsoft Exchange Server 2016 Cumulative Update 23
- Microsoft Microsoft Exchange Server 2019 Cumulative Update 14
- Microsoft Microsoft Exchange Server 2019 Cumulative Update 15
- Microsoft Microsoft Exchange Server Subscription Edition RTM
Weakness type
Related vulnerabilities
- CVE-2026-81524 — Cross-tenant database retargeting via dot/NUL injection in namespace strings in the C Driver
- CVE-2026-81521 — Cross-database write retargeting via unvalidated dotted database name in Client.BulkWrite in the MongoDB Go Driver
- CVE-2026-15186 — macrozheng mall Portal Endpoint create resource injection
- CVE-2026-13493 — AIDC-AI ComfyUI-Copilot Workflow Checkpoint Restore conversation_api.py resource injection
- CVE-2026-12207 — medkey-org medkey HTTP REST API PatientController.php actionGetPatientById resource injection
- CVE-2026-10624 — SourceCodester Human Resource Management Employee View detailview.php resource injection
- CVE-2026-10299 — code-projects Online Hospital Management System viewdoctortimings.php resource injection
- CVE-2026-10168 — OUSL-GROUP-BrinaryBrains School Student Management System Parents.php marks resource injection