CVE-2026-63508
Microsoft Planetary Computer Pro Elevation of Privilege Vulnerability
Description
Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network.
In plain language
AI Act nowCVE-2026-63508 is a serious security flaw in Microsoft Planetary Computer Pro (GeoCatalog)/“planetary computer” that lets a remote attacker gain higher access without logging in; if your business has it exposed to a network, you should act now.
CVE-2026-63508 is an elevation of privilege issue in Microsoft Planetary Computer Pro (GeoCatalog)/planetary computer caused by missing authentication for a critical function, enabling an unauthenticated network attacker to obtain elevated privileges.
What to do now
- Check whether you use Microsoft Planetary Computer Pro (GeoCatalog) or “planetary computer” components, and whether they are reachable from other networks (especially the public internet).
- Open Microsoft’s advisory for CVE-2026-63508 and apply the vendor remediation/update it specifies for your deployment.
- After patching, verify the update completed successfully on every affected server and that the service is running normally.
- If patching is delayed, restrict network access to only trusted internal systems and block direct external access to the Planetary Computer Pro endpoints.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:CScopeC:HConfidentialityI:HIntegrityA:NAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
- Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilitiesen·Cisco Talos· Exploited Windows patch-tuesday
- Microsoft Patch Tuesday, August 2026 Security Update Reviewen-us·Qualys Security Blog· Exploited Windows patch-tuesday
- Microsoft's Patch Tuesday Deluge Continues With August Updatesen·Dark Reading· Exploited Windows patch-tuesday
- Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-daysen-us·BleepingComputer· Exploited Windows Lazarus group
- Microsoft Patch Tuesday August 2026 - SANS ISCen·SANS Internet Storm Center· Exploited Windows zero-day
- ⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoorsen·The Hacker News· Exploited Mythos 5 UNC6671
- Microsoft, Apple Release Fresh Security Updatesen-us·SecurityWeek· Patch Active Directory patch-tuesday
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-63508 and every CVE in our database. Create a free account — no credit card required.
Create Free Account