• PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-54998: authenticated privilege escalation in Microsoft Microsoft Exchange Online

An authorized attacker can elevate privileges on Microsoft Exchange Online, potentially gaining broader access to mailboxes and administrative functions. This is tracked as CVE-2026-54998. Microsoft Exchange Online is listed as affected; the vendor description indicates an incorrect authorization check. The vulnerability requires a network-capable actor with an authorized account and does not require user interaction, according to available information.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
8.8HIGH
EPSS
0.00778
CWE
CWE-863
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: public exploit code exists for CVE-2026-54998, which raises immediate risk to internet-exposed Exchange Online tenants and warrants rapid mitigation or patching per vendor guidance.

What is CVE-2026-54998?

An authorized attacker can elevate privileges on Microsoft Exchange Online, potentially gaining broader access to mailboxes and administrative functions. This is tracked as CVE-2026-54998. Microsoft Exchange Online is listed as affected; the vendor description indicates an incorrect authorization check. The vulnerability requires a network-capable actor with an authorized account and does not require user interaction, according to available information.

Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Which versions of Microsoft Microsoft Exchange Online are affected?

BRANCHAFFECTEDFIXED
Microsoft Exchange Online-

Is CVE-2026-54998 being exploited?

Public exploit code is available for CVE-2026-54998.

How to fix CVE-2026-54998

  1. Apply Microsoft’s official updates or mitigations immediately when published and follow vendor guidance for Exchange Online.
  2. Restrict administrative and privileged account access and enforce least privilege for Exchange Online roles.
  3. Monitor Exchange Online audit logs and privileged account activity for unusual access or escalation attempts.
  4. Limit network exposure of management interfaces and require multi-factor authentication for accounts with elevated privileges.

Frequently asked questions

Is CVE-2026-54998 being actively exploited?

Public exploit code for CVE-2026-54998 is available, increasing the risk of active exploitation against Microsoft Exchange Online.

Which Microsoft Exchange Online versions are affected by CVE-2026-54998?

Microsoft Exchange Online is listed as affected; the vendor description does not specify individual version numbers or builds.

Is there a patch for CVE-2026-54998?

A patch is available according to the facts provided; follow Microsoft’s published guidance for Exchange Online to apply fixes or mitigations.

Does CVE-2026-54998 require authentication?

Yes. The vulnerability requires an authorized attacker account to exploit authorization weaknesses in Microsoft Exchange Online.

References