A CVSS 10.0 improper authentication vulnerability in Microsoft Exchange Online lets an unauthenticated attacker tamper with data over the network.
What Is It
CVE-2026-56191 is an improper authentication vulnerability (CWE-287) in Microsoft Exchange Online. According to Microsoft's disclosure, the flaw "allows an unauthorized attacker to perform tampering over a network." It carries a CVSS 3.1 base score of 10.0 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H, meaning it is exploitable remotely, requires low attack complexity, needs no privileges and no user interaction, and results in a scope change with high impact to confidentiality, integrity, and availability. The vulnerability was published on 2026-07-23 and is tagged as an exclusively-hosted-service issue.
Why It Matters
A perfect 10.0 score is reserved for the most severe vulnerabilities. Here, an attacker requires no credentials and no victim interaction to reach the flaw across the network. The scope change (S:C) indicates the impact can extend beyond the initially vulnerable component, and all three impact metrics, confidentiality, integrity, and availability, are rated HIGH. Because the description specifically calls out tampering by an unauthorized attacker, the integrity of Exchange Online data is directly at risk.
What's Vulnerable
The affected product is Microsoft Exchange Online (vendor: Microsoft). Microsoft lists the affected version as "-" and flags the CVE as an exclusively-hosted-service, indicating this is a cloud-hosted service rather than on-premises software. No specific affected CPE configurations are enumerated in the NVD record.
Patch Status
As an exclusively-hosted-service vulnerability, remediation is handled by Microsoft on the service side; there is no customer-installed patch enumerated in the supplied data. Refer to Microsoft's MSRC update guide entry for the authoritative status. The NVD record's status is "Received," meaning it is still undergoing analysis.
Sources
- NVD, CVE-2026-56191: https://nvd.nist.gov/vuln/detail/CVE-2026-56191
- Microsoft MSRC Update Guide; CVE-2026-56191: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56191