Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 24 Jul 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 24 Jul 2026 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network. | |
| Title | Microsoft Graph Information Disclosure Vulnerability | |
| First Time appeared |
Microsoft
Microsoft graph |
|
| Weaknesses | CWE-200 | |
| CPEs | cpe:2.3:a:microsoft:graph:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Microsoft
Microsoft graph |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: microsoft
Published:
Updated: 2026-07-24T22:08:25.249Z
Reserved: 2026-05-27T23:44:09.622Z
Link: CVE-2026-49159
Updated: 2026-07-24T22:08:21.329Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-24T01:30:03Z