CVE Tools

CVE-2026-65668

Microsoft Purview eDiscovery Elevation of Privilege Vulnerability

Published: Aug 6, 2026Updated: Aug 7, 2026 Sources: CVE List NVDCWE-284

Description

Improper access control in Microsoft Purview eDiscovery allows an authorized attacker to elevate privileges over a network.

In plain language

AI Act now

Microsoft Purview eDiscovery has a permissions flaw where a low-privilege, authenticated attacker could gain higher privileges over the network, so most small businesses using Purview eDiscovery should act to install Microsoft’s fix promptly.

Executive summary

CVE-2026-65668 is an Elevation of Privilege issue in Microsoft Purview eDiscovery caused by improper access controls (CWE-284), where an authorized/low-privileged attacker can trigger a privilege increase over the network without user interaction.

If affected, business impact
Account and permissions takeoverPotential access to sensitive documentsSystem or service disruptionHigher risk of follow-on attacks

What to do now

  1. Check whether your organization uses Microsoft Purview eDiscovery (not just general Purview) and confirm the currently installed/allowed configuration and update level in your environment.
  2. Open the Microsoft MSRC update guidance for CVE-2026-65668 and confirm you are on the fully remediated version/build listed there.
  3. Apply the Microsoft Purview eDiscovery remediation from the MSRC update guide as soon as possible (start with non-production systems first if you need validation).
  4. If you cannot patch immediately, reduce who can authenticate to Purview eDiscovery (tighten access to only required staff/roles) and monitor for abnormal privilege or admin actions related to eDiscovery.
Patch / advisory Some work to apply

CVSS Vector Breakdown

AV:NAC:LPR:LUI:NS:UC:HI:HA:H
Exploitability
AV:NAttack Vector
Network
AC:LAttack Complexity
Low
PR:LPrivileges Required
Low
UI:NUser Interaction
None
Scope
S:UScope
Unchanged
Impact
C:HConfidentiality
High
I:HIntegrity
High
A:HAvailability
High

Weaknesses

Affected Products

Exploitability

Official Patch Available

References

4

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2026-65668 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store