CyberICT

CVE-2026-62906

Microsoft · Published September 3, 2026

CVSS v3.1

HIGH
Patch availableGet patch

Description

Microsoft Discovery Studio Information Disclosure Vulnerability. Improper neutralization of special elements in data query logic in Microsoft Discovery Studio allows an unauthorized attacker to disclose information over a network.

Affected Products

  • Microsoft Discovery Studio

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N/E:U/RL:O/RC:C