CVE-2026-26138Disclosure(microsoft / purview)

LOWCVSS 10.0 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch microsoft purview systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • purview

Threat summary

  • Patch or workaround signal is available
  • 9 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 8 signals
  • Disclosure: 6 classified signals
  • General: 1 classified signal
  • Peaked 4d ago at 2 mentions (2026-03-19); latest day: 1
  • 9 total mentions across 5 days

Affected systems

Vendors
Products
purview

1 version affected across 1 product

Deep dive

Activity timeline9 mentions / 5d
01122Mentions · 2026-03-19: 2Mentions · 2026-03-20: 2Mentions · 2026-03-22: 2Mentions · 2026-03-24: 2Mentions · 2026-03-31: 1Patch / Workaround · 2026-03-20: 1Patch / Workaround · 2026-03-24: 1Technical Details · 2026-03-19: 2Technical Details · 2026-03-20: 1Technical Details · 2026-03-22: 2Technical Details · 2026-03-24: 2Technical Details · 2026-03-31: 103-1903-2003-2203-2403-31
Signal classification3 categories
Disclosure
666.7%
Patch
222.2%
General
111.1%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-03-192
Disclosure2
2026-03-202
General1Patch1
2026-03-222
Disclosure2
2026-03-242
Disclosure1Patch1
2026-03-311
Disclosure1
Full discourse9 posts
  • kawn@kawn2020
    Patch

    #securityupdate #microsoft #定例外 2026. 3.19 Microsoft Purview の特権昇格の脆弱性 CVE-2026-26138 Security Vulnerability リリース日: - マイクロソフト https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26138

    Post summary

    Microsoft has disclosed a privilege‑escalation flaw (CVE-2026-26138) in Purview, linking to its security update advisory, but it does not mention a PoC, exploit, or active exploitation.

    1010078
    88 followersView on X
  • dbugs@ptdbugs
    Patch

    Microsoft Purview Elevation of Privilege Vulnerability CVE: CVE-2026-26138 PT-Identifier: PT-2026-26356 Vendor: Microsoft Product: Microsoft Purview CVSS: 8.6 Credits: n/a Description: Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-26138 • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26138 #dbugs_vuln

    Post summary

    The text announces a server‑side request forgery (SSRF) vulnerability (CVE‑2026‑26138) in Microsoft Purview that enables privilege escalation, with a CVSS score of 8.6 and an available Microsoft patch, but provides no PoC, exploit code, or evidence of active exploitation.

    0001178
    649 followersView on X
  • kawn@kawn2020
    Disclosure

    #securityupdate #microsoft #定例外 CVE-2026-26138 Security Vulnerability 影響: 特権の昇格 最大深刻度: 緊急 CVSS:3.1 8.6 / 7.7 悪用可能性 ・一般に公開: No ・悪用: No ・Exploitability assessment: 対象外 https://x.com/kawn2020/status/2036266522382049717

    Post summary

    Microsoft announces CVE-2026-26138, a privilege‑escalation vulnerability with CVSS scores 8.6/7.7, reporting no active exploitation or PoC and offering no patch information.

    1000040
    88 followersView on X
  • Aakash Rahsi@rahsi_aaka
    Disclosure

    CVE-2026-26138 | Microsoft Purview Elevation of Privilege Vulnerability https://www.aakashrahsi.online/post/cve-2026-26138 https://t.co/VjSM3XbN3C

    Post summary

    The tweet is a concise announcement of a newly disclosed Microsoft Purview privilege escalation vulnerability (CVE‑2026‑26138), providing links for additional details.

    0000036
    1 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-26138 Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network. https://www.cve.org/CVERecord?id=CVE-2026-26138 ----- Traducción: CVE-2026-26138 SSRF (solicitud entre servidor) en Microsoft P… http://infoflow.cloud`

    Post summary

    A new SSRF vulnerability (CVE-2026-26138) in Microsoft Purview is disclosed, granting unauthorized privilege escalation across the network. No exploit code, patch, or active exploitation details are provided.

    0000027
    61 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-26138 Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network. https://www.cve.org/CVERecord?id=CVE-2026-26138

    Post summary

    The text announces CVE-2026-26138 as an SSRF vulnerability in Microsoft Purview that can lead to privilege escalation, linking to the CVE record.

    00000212
    56.8K followersView on X
  • RedPacket Security@RedPacketSec
    General

    CVE Alert: CVE-2026-26138 - Microsoft - Microsoft Purview - https://www.redpacketsecurity.com/cve-alert-cve-2026-26138-microsoft-microsoft-purview/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-26138 #microsoft #microsoft-purview

    Post summary

    The post identifies CVE-2026-26138 and provides a link, but supplies no further details about exploitation, patching, or technical characteristics.

    0000051
    3.6K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-26138 - High Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network. https://www.thehackerwire.com/vulnerability/CVE-2026-26138/ https://t.co/r7DpPGtUxZ

    Post summary

    The tweet announces a high‑severity server‑side request forgery vulnerability (CVE‑2026‑26138) in Microsoft Purview that could enable privilege escalation, but does not provide any PoC, exploit, or patch details.

    0000044
    137 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-26138: HIGH] Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network.#cve,CVE-2026-26138,#cybersecurity https://cvefind.com/CVE-2026-26138

    Post summary

    The post announces a high‑severity SSRF flaw in Microsoft Purview that could enable privilege escalation, but provides no PoC, exploitation evidence, or patch info.

    0000070
    603 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftpurview---

Explore more