Description
Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Fri, 24 Jul 2026 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network. | |
| Title | Microsoft Graph Information Disclosure Vulnerability | |
| First Time appeared |
Microsoft
Microsoft graph |
|
| Weaknesses | CWE-200 | |
| CPEs | cpe:2.3:a:microsoft:graph:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Microsoft
Microsoft graph |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: microsoft
Published:
Updated: 2026-07-24T19:36:25.752Z
Reserved: 2026-05-27T23:44:09.622Z
Link: CVE-2026-49159
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-24T01:30:03Z
Weaknesses