CVE-2026-26139General(microsoft / purview)

LOWCVSS 8.6 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • purview

Threat summary

  • 9 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 6 signals
  • General: 5 classified signals
  • Disclosure: 4 classified signals
  • Peaked 3d ago at 2 mentions (2026-03-20); latest day: 2
  • 9 total mentions across 5 days

Affected systems

Vendors
Products
purview

1 version affected across 1 product

Deep dive

Activity timeline9 mentions / 5d
01122Mentions · 2026-03-19: 1Mentions · 2026-03-20: 2Mentions · 2026-03-22: 2Mentions · 2026-03-24: 2Mentions · 2026-03-31: 2Technical Details · 2026-03-19: 1Technical Details · 2026-03-20: 1Technical Details · 2026-03-22: 2Technical Details · 2026-03-24: 203-1903-2003-2203-2403-31
Signal classification2 categories
General
555.6%
Disclosure
444.4%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-03-191
Disclosure1
2026-03-202
General2
2026-03-222
Disclosure2
2026-03-242
Disclosure1General1
2026-03-312
General2
Full discourse9 posts
  • kawn@kawn2020
    Disclosure

    #securityupdate #microsoft #定例外 2026. 3.19 Microsoft Purview の特権昇格の脆弱性 CVE-2026-26139 Security Vulnerability リリース日: - マイクロソフト https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26139

    Post summary

    Microsoft disclosed a privilege‑escalation flaw (CVE‑2026‑26139) in Purview, providing a link to the official Microsoft Security Response Center update guide.

    1010075
    88 followersView on X
  • kawn@kawn2020
    General

    #securityupdate #microsoft #定例外 CVE-2026-26139 Security Vulnerability 影響: 特権の昇格 最大深刻度: 緊急 CVSS:3.1 8.6 / 7.7 悪用可能性 ・一般に公開: No ・悪用: No ・Exploitability assessment: 対象外 https://x.com/kawn2020/status/2036267302715601399

    Post summary

    A status update announcing CVE-2026-26139 as a privilege escalation vulnerability with emergency severity, but no PoC, active exploitation, patch, or further technical detail beyond severity scores is provided.

    1000038
    88 followersView on X
  • Aakash Rahsi@rahsi_aaka
    General

    CVE-2026-26139 | Microsoft Purview Elevation of Privilege Vulnerability https://www.aakashrahsi.online/post/cve-2026-26139 https://t.co/9QZEVoUH6c

    Post summary

    The snippet briefly mentions a Microsoft Purview elevation‑of‑privilege CVE (CVE‑2026‑26139) but lacks any concrete technical details, PoC links, exploit code, patches, or evidence of active exploitation.

    0000032
    1 followersView on X
  • Aakash Rahsi@rahsi_aaka
    General

    CVE-2026-26139 | Microsoft Purview Elevation of Privilege Vulnerability https://www.aakashrahsi.online/post/cve-2026-26139 https://t.co/0KRTNLu0lz

    Post summary

    The post lists CVE‑2026‑26139 as a Microsoft Purview elevation‑of‑privilege issue and provides a link, but offers no additional details or actionable information.

    0000033
    1 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-26139 Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network. https://www.cve.org/CVERecord?id=CVE-2026-26139 ----- Traducción: CVE-2026-26139 Falsificación de solicitudes del lado del serv… http://infoflow.cloud`

    Post summary

    The post announces a new vulnerability (CVE-2026-26139) describing an SSRF that can lead to privilege escalation, but it does not provide exploitation evidence, a PoC, or a patch.

    0000035
    61 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-26139 Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network. https://www.cve.org/CVERecord?id=CVE-2026-26139

    Post summary

    The text discloses a SSRF vulnerability in Microsoft Purview that could lead to privilege escalation over a network, but provides no evidence of exploitation, PoC, or patch.

    00000206
    56.8K followersView on X
  • dbugs@ptdbugs
    General

    Microsoft Purview Elevation of Privilege Vulnerability CVE: CVE-2026-26139 PT-Identifier: PT-2026-26357 Vendor: Microsoft Product: Microsoft Purview CVSS: 8.6 Credits: n/a Description: Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-26139 • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26139 #dbugs_vuln

    Post summary

    This is a disclosure of an SSRF‑based privilege escalation in Microsoft Purview with a CVSS of 8.6; no PoC, exploit, or patch information is provided.

    0000048
    649 followersView on X
  • RedPacket Security@RedPacketSec
    General

    CVE Alert: CVE-2026-26139 - Microsoft - Microsoft Purview - https://www.redpacketsecurity.com/cve-alert-cve-2026-26139-microsoft-microsoft-purview/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-26139 #microsoft #microsoft-purview

    Post summary

    The tweet links to an external CVE alert but contains no additional details about proof‑of‑concepts, exploits, active usage, patches, or technical specifics.

    0000056
    3.6K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-26139: HIGH] Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network.#cve,CVE-2026-26139,#cybersecurity https://cvefind.com/CVE-2026-26139

    Post summary

    A high‑severity SSRF vulnerability (CVE‑2026‑26139) in Microsoft Purview has been disclosed, enabling unauthorized attackers to elevate privileges, but the post contains no PoC, exploit or patch details.

    0000064
    603 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftpurview---

Explore more