🟠 High  |  Source: Microsoft Security Response Center


A missing authentication flaw in Microsoft Planetary Computer Pro allows an unauthenticated attacker to elevate their privileges over a network without requiring any user interaction. This means an attacker with network access could gain higher-level permissions than intended, potentially compromising sensitive geospatial and environmental data workloads hosted on the platform. The lack of any authentication requirement makes this relatively straightforward to exploit.

Security Architect’s Take: Review whether your organisation uses Microsoft Planetary Computer Pro and apply any available patches or mitigations from Microsoft immediately. In the interim, consider restricting network access to the service using Azure network security controls such as private endpoints, NSGs, or Azure Firewall to limit exposure until a fix is confirmed in place.

Original advisory: CVE-2026-63508 Microsoft Planetary Computer Pro Elevation of Privilege Vulnerability