CVE-2026-42826
Microsoft · Published May 7, 2026
10.0
CVSS v3.1
CRITICALPatch availableGet patch
Description
Azure DevOps Information Disclosure Vulnerability. Exposure of sensitive information to an unauthorized actor in Azure DevOps allows an unauthorized attacker to disclose information over a network.
Affected Products
- Azure DevOps
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C