CVE-2026-65668
Microsoft Purview eDiscovery Elevation of Privilege Vulnerability
Description
Improper access control in Microsoft Purview eDiscovery allows an authorized attacker to elevate privileges over a network.
In plain language
AI Act nowMicrosoft Purview eDiscovery has a permissions flaw where a low-privilege, authenticated attacker could gain higher privileges over the network, so most small businesses using Purview eDiscovery should act to install Microsoft’s fix promptly.
CVE-2026-65668 is an Elevation of Privilege issue in Microsoft Purview eDiscovery caused by improper access controls (CWE-284), where an authorized/low-privileged attacker can trigger a privilege increase over the network without user interaction.
What to do now
- Check whether your organization uses Microsoft Purview eDiscovery (not just general Purview) and confirm the currently installed/allowed configuration and update level in your environment.
- Open the Microsoft MSRC update guidance for CVE-2026-65668 and confirm you are on the fully remediated version/build listed there.
- Apply the Microsoft Purview eDiscovery remediation from the MSRC update guide as soon as possible (start with non-production systems first if you need validation).
- If you cannot patch immediately, reduce who can authenticate to Purview eDiscovery (tighten access to only required staff/roles) and monitor for abnormal privilege or admin actions related to eDiscovery.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
References
- Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilitiesen·Cisco Talos· Exploited Windows patch-tuesday
- Microsoft Patch Tuesday, August 2026 Security Update Reviewen-us·Qualys Security Blog· Exploited Windows patch-tuesday
- Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-daysen-us·BleepingComputer· Exploited Windows Lazarus group
- Microsoft Patch Tuesday August 2026 - SANS ISCen·SANS Internet Storm Center· Exploited Windows zero-day
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-65668 and every CVE in our database. Create a free account — no credit card required.
Create Free Account