Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network.
cve CVE-2026-96940 2 sources, 2 claims · Watch
NVD writes:
Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network. the claim
Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network. the claim
What it is to other things
In words only, so not counted until a person confirms one:
| affects | microsoft/microsoft_exchange_server_2016_cumulative_update_23NVD says “Microsoft · Microsoft Exchange Server 2016 Cumulative Update 23” |
| made_by | microsoftNVD says “Microsoft” |
What each source says
| Property | Source | Said | Means here |
|---|---|---|---|
| Cvss cvss | GitHub advisories | 8.8receipt
What the source handed over{
"comments": 0,
"credits": [],
"cve_id": "CVE-2026-96940",
"cvss": {
"score": 8.8,
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
},
"cvss_severities": {
"cvss_v3": {
"score": 8.8,
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
},
"cvss_v4": {
"score": 0.0,
"vector_string": null
}
},
"cwes": [
{
"cwe_id": "CWE-1390",
"name": "Weak Authentication"
}
],
"description": "Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network.",
"ghsa_id": "GHSA-q9jh-jffv-9xvh",
"github_reviewed_at": null,
"html_url": "https://github.com/advisories/GHSA-q9jh-jffv-9xvh",
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-q9jh-jffv-9xvh"
},
{
"type": "CVE",
"value": "CVE-2026-96940"
}
],
"nvd_published_at": "2026-10-02T19:16:43Z",
"published_at": "2026-10-02T21:32:05Z",
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2026-96940",
"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-96940",
"https://github.com/advisories/GHSA-q9jh-jffv-9xvh"
],
"repository_advisory_url": null,
"severity": "high",
"source_code_location": "",
"summary": "Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate...",
"type": "unreviewed",
"updated_at": "2026-10-02T21:32:13Z",
"url": "https://api.github.com/advisories/GHSA-q9jh-jffv-9xvh",
"vulnerabilities": [],
"withdrawn_at": null
} | — |
| Cvss cvss | NVD | 8.8receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"platforms": [
"x64-based Systems"
],
"product": "Microsoft Exchange Server 2016 Cumulative Update 23",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "15.01.2507.075",
"status": "affected",
"version": "15.01.0.0",
"versionType": "custom"
}
]
},
{
"platforms": [
"x64-based Systems"
],
"product": "Microsoft Exchange Server 2019 Cumulative Update 14",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "15.02.1544.048",
"status": "affected",
"version": "15.02.0.0",
"versionType": "custom"
}
]
},
{
"platforms": [
"x64-based Systems"
],
"product": "Microsoft Exchange Server 2019 Cumulative Update 15",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "15.02.1748.053",
"status": "affected",
"version": "15.02.0.0",
"versionType": "custom"
}
]
},
{
"platforms": [
"x64-based Systems"
],
"product": "Microsoft Exchange Server Subscription Edition RTM",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "15.02.2562.053",
"status": "affected",
"version": "15.02.0.0",
"versionType": "custom"
}
]
}
],
"source": "secure@microsoft.com"
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network."
}
],
"id": "CVE-2026-96940",
"lastModified": "2026-10-02T21:16:58.060",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 2.8,
"impactScore": 5.9,
"source": "secure@microsoft.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-96940",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-02T20:14:42.856638Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-10-02T19:16:43.023",
"references": [
{
"source": "secure@microsoft.com",
"url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-96940"
}
],
"sourceIdentifier": "secure@microsoft.com",
"vulnStatus": "Received",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-1390"
}
],
"source": "secure@microsoft.com",
"type": "Secondary"
}
]
}
} | — |
| Cwe cwe | GitHub advisories | CWE-1390receipt
What the source handed over{
"comments": 0,
"credits": [],
"cve_id": "CVE-2026-96940",
"cvss": {
"score": 8.8,
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
},
"cvss_severities": {
"cvss_v3": {
"score": 8.8,
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
},
"cvss_v4": {
"score": 0.0,
"vector_string": null
}
},
"cwes": [
{
"cwe_id": "CWE-1390",
"name": "Weak Authentication"
}
],
"description": "Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network.",
"ghsa_id": "GHSA-q9jh-jffv-9xvh",
"github_reviewed_at": null,
"html_url": "https://github.com/advisories/GHSA-q9jh-jffv-9xvh",
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-q9jh-jffv-9xvh"
},
{
"type": "CVE",
"value": "CVE-2026-96940"
}
],
"nvd_published_at": "2026-10-02T19:16:43Z",
"published_at": "2026-10-02T21:32:05Z",
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2026-96940",
"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-96940",
"https://github.com/advisories/GHSA-q9jh-jffv-9xvh"
],
"repository_advisory_url": null,
"severity": "high",
"source_code_location": "",
"summary": "Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate...",
"type": "unreviewed",
"updated_at": "2026-10-02T21:32:13Z",
"url": "https://api.github.com/advisories/GHSA-q9jh-jffv-9xvh",
"vulnerabilities": [],
"withdrawn_at": null
} | — |
| Product product | NVD | Microsoft Exchange Server 2016 Cumulative Update 23receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"platforms": [
"x64-based Systems"
],
"product": "Microsoft Exchange Server 2016 Cumulative Update 23",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "15.01.2507.075",
"status": "affected",
"version": "15.01.0.0",
"versionType": "custom"
}
]
},
{
"platforms": [
"x64-based Systems"
],
"product": "Microsoft Exchange Server 2019 Cumulative Update 14",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "15.02.1544.048",
"status": "affected",
"version": "15.02.0.0",
"versionType": "custom"
}
]
},
{
"platforms": [
"x64-based Systems"
],
"product": "Microsoft Exchange Server 2019 Cumulative Update 15",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "15.02.1748.053",
"status": "affected",
"version": "15.02.0.0",
"versionType": "custom"
}
]
},
{
"platforms": [
"x64-based Systems"
],
"product": "Microsoft Exchange Server Subscription Edition RTM",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "15.02.2562.053",
"status": "affected",
"version": "15.02.0.0",
"versionType": "custom"
}
]
}
],
"source": "secure@microsoft.com"
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network."
}
],
"id": "CVE-2026-96940",
"lastModified": "2026-10-02T21:16:58.060",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 2.8,
"impactScore": 5.9,
"source": "secure@microsoft.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-96940",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-02T20:14:42.856638Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-10-02T19:16:43.023",
"references": [
{
"source": "secure@microsoft.com",
"url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-96940"
}
],
"sourceIdentifier": "secure@microsoft.com",
"vulnStatus": "Received",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-1390"
}
],
"source": "secure@microsoft.com",
"type": "Secondary"
}
]
}
} | — |
| Severity severity | GitHub advisories | high From 7.0 to 8.9. receipt
What the source handed over{
"comments": 0,
"credits": [],
"cve_id": "CVE-2026-96940",
"cvss": {
"score": 8.8,
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
},
"cvss_severities": {
"cvss_v3": {
"score": 8.8,
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
},
"cvss_v4": {
"score": 0.0,
"vector_string": null
}
},
"cwes": [
{
"cwe_id": "CWE-1390",
"name": "Weak Authentication"
}
],
"description": "Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network.",
"ghsa_id": "GHSA-q9jh-jffv-9xvh",
"github_reviewed_at": null,
"html_url": "https://github.com/advisories/GHSA-q9jh-jffv-9xvh",
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-q9jh-jffv-9xvh"
},
{
"type": "CVE",
"value": "CVE-2026-96940"
}
],
"nvd_published_at": "2026-10-02T19:16:43Z",
"published_at": "2026-10-02T21:32:05Z",
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2026-96940",
"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-96940",
"https://github.com/advisories/GHSA-q9jh-jffv-9xvh"
],
"repository_advisory_url": null,
"severity": "high",
"source_code_location": "",
"summary": "Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate...",
"type": "unreviewed",
"updated_at": "2026-10-02T21:32:13Z",
"url": "https://api.github.com/advisories/GHSA-q9jh-jffv-9xvh",
"vulnerabilities": [],
"withdrawn_at": null
} | — |
| Status status | NVD | Receivedreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"platforms": [
"x64-based Systems"
],
"product": "Microsoft Exchange Server 2016 Cumulative Update 23",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "15.01.2507.075",
"status": "affected",
"version": "15.01.0.0",
"versionType": "custom"
}
]
},
{
"platforms": [
"x64-based Systems"
],
"product": "Microsoft Exchange Server 2019 Cumulative Update 14",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "15.02.1544.048",
"status": "affected",
"version": "15.02.0.0",
"versionType": "custom"
}
]
},
{
"platforms": [
"x64-based Systems"
],
"product": "Microsoft Exchange Server 2019 Cumulative Update 15",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "15.02.1748.053",
"status": "affected",
"version": "15.02.0.0",
"versionType": "custom"
}
]
},
{
"platforms": [
"x64-based Systems"
],
"product": "Microsoft Exchange Server Subscription Edition RTM",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "15.02.2562.053",
"status": "affected",
"version": "15.02.0.0",
"versionType": "custom"
}
]
}
],
"source": "secure@microsoft.com"
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network."
}
],
"id": "CVE-2026-96940",
"lastModified": "2026-10-02T21:16:58.060",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 2.8,
"impactScore": 5.9,
"source": "secure@microsoft.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-96940",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-02T20:14:42.856638Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-10-02T19:16:43.023",
"references": [
{
"source": "secure@microsoft.com",
"url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-96940"
}
],
"sourceIdentifier": "secure@microsoft.com",
"vulnStatus": "Received",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-1390"
}
],
"source": "secure@microsoft.com",
"type": "Secondary"
}
]
}
} | — |
| Vendor vendor | NVD | Microsoftreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"platforms": [
"x64-based Systems"
],
"product": "Microsoft Exchange Server 2016 Cumulative Update 23",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "15.01.2507.075",
"status": "affected",
"version": "15.01.0.0",
"versionType": "custom"
}
]
},
{
"platforms": [
"x64-based Systems"
],
"product": "Microsoft Exchange Server 2019 Cumulative Update 14",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "15.02.1544.048",
"status": "affected",
"version": "15.02.0.0",
"versionType": "custom"
}
]
},
{
"platforms": [
"x64-based Systems"
],
"product": "Microsoft Exchange Server 2019 Cumulative Update 15",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "15.02.1748.053",
"status": "affected",
"version": "15.02.0.0",
"versionType": "custom"
}
]
},
{
"platforms": [
"x64-based Systems"
],
"product": "Microsoft Exchange Server Subscription Edition RTM",
"vendor": "Microsoft",
"versions": [
{
"lessThan": "15.02.2562.053",
"status": "affected",
"version": "15.02.0.0",
"versionType": "custom"
}
]
}
],
"source": "secure@microsoft.com"
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network."
}
],
"id": "CVE-2026-96940",
"lastModified": "2026-10-02T21:16:58.060",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"exploitabilityScore": 2.8,
"impactScore": 5.9,
"source": "secure@microsoft.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-96940",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-02T20:14:42.856638Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-10-02T19:16:43.023",
"references": [
{
"source": "secure@microsoft.com",
"url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-96940"
}
],
"sourceIdentifier": "secure@microsoft.com",
"vulnStatus": "Received",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-1390"
}
],
"source": "secure@microsoft.com",
"type": "Secondary"
}
]
}
} | — |
vulnerability
| Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network. zetlyn/cve-nvd · 2026-10-02 | cvss 8.8 product Microsoft Exchange Server 2016 Cumulative Update 23 status Received vendor Microsoft | source |
| Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate... zetlyn/cve-ghsa · 2026-10-02 | cvss 8.8 cwe CWE-1390 severity high | source |