🟠 High  |  Source: Microsoft Security Response Center


A vulnerability in Microsoft Purview eDiscovery allows an attacker who already has some level of authorised access to gain higher privileges over a network due to improper access controls. This is particularly concerning in environments where eDiscovery is used to handle sensitive legal, compliance, or HR data. Successful exploitation could allow an attacker to access or manipulate data and configurations far beyond their intended permissions.

Security Architect’s Take: Review who holds any level of access to your Microsoft Purview eDiscovery environment and apply the principle of least privilege immediately. Monitor Microsoft’s patch guidance and apply available mitigations or updates promptly, whilst auditing recent eDiscovery role assignments for anomalous privilege changes.

Original advisory: CVE-2026-65668 Microsoft Purview eDiscovery Elevation of Privilege Vulnerability