🟠 High  |  Source: Microsoft Security Response Center


CVE-2026-62835 is an improper authorisation vulnerability in Microsoft Online Services that allows an unauthenticated attacker to access information they should not be able to see, exploitable remotely over a network. The flaw stems from insufficient access controls, meaning no credentials are required to trigger it. This makes it a meaningful risk for organisations relying on affected Azure-connected online services to protect sensitive data.

Security Architect’s Take: Review your Azure Online Services exposure and monitor Microsoft’s update guide for affected service specifics and any available mitigations or patches; consider enabling enhanced logging and alerting on anomalous read activity across your online services estate until a fix is confirmed deployed.

Original advisory: CVE-2026-62835 Online Services Information Disclosure Vulnerability