CVE-2026-49159: Microsoft Graph Information Disclosure Vulnerability
Published Jul 23, 2026
·Updated
Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network.
Other sources
Microsoft Graph Information Disclosure Vulnerability
— Microsoft
Affected Software
1 affected component
Microsoft Graph
Event History
Jul 23, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·02:00 PM
Description
Jul 24, 2026
CVE Published
via MITRE·12:01 AM
Data Sourced
via MITRE·12:01 AM
DescriptionSeverity
Data Sourced
via NVD·01:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-49159?
CVE-2026-49159 has a medium severity rating of 6.5.
2
How do I fix CVE-2026-49159?
To mitigate CVE-2026-49159, ensure that you are using the latest version of Microsoft Graph with all security patches applied.
3
What type of vulnerability is CVE-2026-49159?
CVE-2026-49159 is classified as an information disclosure vulnerability.
4
What potential impact does CVE-2026-49159 have?
CVE-2026-49159 may allow unauthorized actors to disclose sensitive information over a network.
5
When was CVE-2026-49159 published?
CVE-2026-49159 was published on July 23, 2026.