Back to vendor advisories
Microsoft Security Response CenterCVE-2026-94510

Microsoft Bookings Elevation of Privilege Vulnerability

CriticalVendor CVSS 9.9 / 10 1 CVE Published Oct 8, 2026 at 7:00 AM UTC

Summary

Authorization bypass through user-controlled key in Microsoft Bookings allows an unauthorized attacker to elevate privileges over a network.

Products covered

  • Azure API Center

Remediation

Separate remediation guidance was not included in the collected bulletin.

CVEs in this advisory 1

Updates

  1. Published by Microsoft Security Response Center

    The publication date reported by the vendor.

  2. Added to SecurityAlert

    We collected the advisory from the official source.