🟠 High | Source: Microsoft Security Response Center
CVE-2026-62835 is an improper authorisation vulnerability in Microsoft Online Services that allows an unauthenticated attacker to access information they should not be able to see, exploitable remotely over a network. The flaw stems from insufficient access controls, meaning no credentials are required to trigger it. This makes it a meaningful risk for organisations relying on affected Azure-connected online services to protect sensitive data.
Security Architect’s Take: Review your Azure Online Services exposure and monitor Microsoft’s update guide for affected service specifics and any available mitigations or patches; consider enabling enhanced logging and alerting on anomalous read activity across your online services estate until a fix is confirmed deployed.
Original advisory: CVE-2026-62835 Online Services Information Disclosure Vulnerability