• PATCH AVAILABLE

CVE-2026-69843: authentication bypass in Microsoft Microsoft Fabric

An unauthenticated remote attacker can bypass authentication and elevate privileges in Microsoft Fabric, potentially gaining full control of affected instances. CVE-2026-69843 is reported as an authentication bypass (CWE-290) with a CVSS 3.1 score of 10.0. The vendor identifies the issue in the Microsoft Fabric branch; specific fixed versions are not listed in the available data. Exploitation requires network access to the product and does not require valid credentials or user interaction.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
10CRITICAL
EPSS
0.00901
CWE
CWE-290
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: treat this as high priority because the flaw allows unauthenticated network access to bypass authentication. Immediately follow vendor guidance and reduce external exposure while you prepare to apply updates.

What is CVE-2026-69843?

An unauthenticated remote attacker can bypass authentication and elevate privileges in Microsoft Fabric, potentially gaining full control of affected instances. CVE-2026-69843 is reported as an authentication bypass (CWE-290) with a CVSS 3.1 score of 10.0. The vendor identifies the issue in the Microsoft Fabric branch; specific fixed versions are not listed in the available data. Exploitation requires network access to the product and does not require valid credentials or user interaction.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Which versions of Microsoft Microsoft Fabric are affected?

BRANCHAFFECTEDFIXED
Microsoft Fabric-

Is CVE-2026-69843 being exploited?

There are no public reports of exploitation as of 2026-09-30.

How to fix CVE-2026-69843

  1. Apply the vendor's security guidance and updates for Microsoft Fabric as soon as they are available.
  2. If official fixed versions are published, install those patches immediately; otherwise follow any vendor mitigations.
  3. Restrict network exposure of Microsoft Fabric instances to trusted networks and management subnets.
  4. Monitor logs and authentication events for unexpected privilege changes and suspicious activity.

Frequently asked questions

Is CVE-2026-69843 being actively exploited?

There are no public reports of exploitation of CVE-2026-69843 as of 2026-09-30.

Which Microsoft Fabric versions are affected by CVE-2026-69843?

The vulnerability is reported for the Microsoft Fabric branch; the available data does not list specific affected or fixed version numbers.

Is there a patch for CVE-2026-69843?

A patch is indicated as available by the vendor, but specific fixed version identifiers are not provided in the available information; follow Microsoft guidance and apply updates when published.

Does CVE-2026-69843 require authentication?

No, the vulnerability allows authentication bypass and does not require valid credentials or user interaction to exploit.

References