CVE-2026-49159
Microsoft · Published July 23, 2026
6.5
CVSS v3.1
MEDIUMPatch availableGet patch
Description
Microsoft Graph Information Disclosure Vulnerability. Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network.
Affected Products
- Microsoft Graph
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C