PT-2026-47976 · Microsoft · Exchange Server

CVE-2026-45504

·

Published

2026-06-09

·

Updated

2026-08-14

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Exchange Server (affected versions not specified)
Description An elevation-of-privilege issue exists due to a server-side request forgery (SSRF) flaw. This occurs because of insufficient input validation of URLs in the attachment preview and WOPI (Web Open Word Processor Interface) handling. An authenticated, low-privileged user can exploit this by manipulating the WebApplicationUrl variable and using a # fragment to bypass appended parameters, forcing the server to read arbitrary local files. This allows the attacker to extract sensitive data and elevate privileges over a network.
Recommendations Apply the Microsoft June 2026 security updates. Restrict outbound connections from Exchange servers to untrusted endpoints. Restrict unnecessary external access and review hybrid configurations.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-08295
CVE-2026-45504

Affected Products

Exchange Server