SYS::ONLINE
Wasteland.
Briefs1769
Issues22
SinceFeb 2026
LIVE
CVE · Critical CVE-2026-63508 2026-08-06

CVE-2026-63508: Missing Authentication in Microsoft Planetary Computer Pro Scores a Perfect 10.0

"Microsoft disclosed a maximum-severity flaw in Planetary Computer Pro (GeoCatalog) that lets an unauthenticated, remote attacker elevate privileges across a security boundary."

Microsoft disclosed a maximum-severity flaw in Planetary Computer Pro (GeoCatalog) that lets an unauthenticated, remote attacker elevate privileges across a security boundary.

What Is It

CVE-2026-63508 is a missing authentication for critical function vulnerability (CWE-306) in Microsoft Planetary Computer Pro. Per Microsoft's description, the flaw "allows an unauthorized attacker to elevate privileges over a network."

The CVSS 3.1 base score is 10.0 (CRITICAL), vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N. Every exploitability metric is worst-case: network-reachable, low attack complexity, no privileges required, and no user interaction. Scope is Changed, meaning the impact crosses out of the vulnerable component's security authority; that scope change is what pushes the score to a full 10.0. Confidentiality and integrity impact are both High; availability impact is None.

The record was published by Microsoft ([email protected]) and currently carries NVD status Received, meaning NVD analysis is not yet complete. Every detail above, the description, the CVSS vector and score, and the CWE-306 mapping, comes from Microsoft acting as the CNA for its own product. Nothing in the record has been independently corroborated, and the assigned values may change once NVD completes its analysis.

Why It Matters

A critical function that performs no authentication check, reachable over the network with zero prerequisites, is about as low a bar to exploitation as a vulnerability can present. The combination of no required privileges, no user interaction, and a changed scope with High confidentiality and integrity impact means a successful attacker gains elevated privileges affecting resources beyond the initially vulnerable component.

That said, the severity rating is a characterization of the flaw as the vendor describes it, not a report of observed attacks. The available record says nothing about exploitation activity in either direction, and the sparse entry gives defenders little to work with beyond the metrics themselves; no attack detail, no affected component, no indicators.

What's Vulnerable

Microsoft tagged this CVE exclusively-hosted-service. No affected CPEs are listed in the NVD record. The unversioned entry and absent CPE data are what a hosted-service disclosure normally looks like; they do not narrow which deployments or which service components were affected.

Patch Status

No patch, build number, or fixed version is specified in the supplied data. The exclusively-hosted-service tag indicates the vulnerability exists in a service Microsoft operates, where remediation is applied on the vendor side rather than by customer-installed updates. No customer-required action is stated in the source material; though the absence of a stated action is not the same as a vendor confirmation that none is needed. Consult the MSRC update guide entry below for authoritative status.

Sources