PT-2026-47976 · Microsoft · Exchange Server
CVE-2026-45504
·
Published
2026-06-09
·
Updated
2026-08-14
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Exchange Server (affected versions not specified)
Description
An elevation-of-privilege issue exists due to a server-side request forgery (SSRF) flaw. This occurs because of insufficient input validation of URLs in the attachment preview and WOPI (Web Open Word Processor Interface) handling. An authenticated, low-privileged user can exploit this by manipulating the
WebApplicationUrl variable and using a # fragment to bypass appended parameters, forcing the server to read arbitrary local files. This allows the attacker to extract sensitive data and elevate privileges over a network.Recommendations
Apply the Microsoft June 2026 security updates.
Restrict outbound connections from Exchange servers to untrusted endpoints.
Restrict unnecessary external access and review hybrid configurations.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Exchange Server