🟠 High  |  Source: Microsoft Security Response Center


CVE-2026-49159 is an information disclosure vulnerability in Microsoft Graph, the API layer underpinning much of Microsoft 365 and Azure. An authenticated attacker can exploit this flaw over a network to access sensitive data they should not be able to see. Because Microsoft Graph is widely used to access emails, calendar data, user profiles, and organisational data, the potential exposure is significant.

Security Architect’s Take: Review your Microsoft Graph API permissions and enforce least-privilege OAuth scopes across all registered applications and service principals; monitor Azure AD sign-in and Graph audit logs for anomalous data access patterns while Microsoft’s patch or mitigation guidance is confirmed and applied.

Original advisory: CVE-2026-49159 Microsoft Graph Information Disclosure Vulnerability