Cyber & AI intelligence
Wasteland.
Briefs indexed3091
Issues31
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-94510 2026-10-08

CVE-2026-94510: Critical Authorization Bypass in Microsoft Bookings

"CVE-2026-94510 is a critical (CVSS 9.9) authorization bypass flaw in Microsoft Bookings that lets an unauthorized attacker elevate privileges over a network."

CVE-2026-94510 is a critical (CVSS 9.9) authorization bypass flaw in Microsoft Bookings that lets an unauthorized attacker elevate privileges over a network.

What Is It

Microsoft describes CVE-2026-94510 as an "authorization bypass through user-controlled key" in Microsoft Bookings. It is classified as CWE-639 (Authorization Bypass Through User-Controlled Key). This class of flaw occurs when an application uses a value the user can change to decide what data or functions they may access. The result is privilege escalation over a network.

Microsoft ([email protected]) published the record to NVD on 2026-10-08. Its NVD status is currently "Received," so NVD has not yet completed its own analysis.

Why It Matters

Microsoft rates the flaw 9.9 CRITICAL under CVSS 3.1, with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:L:

An unauthenticated attacker who can reach the service could exploit it with little effort. The exploitability subscore is 3.9 and the impact subscore is 5.3.

Exploitation status: The supplied data contains no CISA Known Exploited Vulnerabilities (KEV) entry for this CVE. KEV does not currently confirm active exploitation, and the supplied sources contain no other evidence of exploitation.

What's Vulnerable

Microsoft has tagged the CVE exclusively-hosted-service, which means Microsoft Bookings runs as a Microsoft-hosted service rather than as software customers install themselves. The record lists no CPE entries.

Patch Status

The supplied sources give no specific remediation steps or required customer actions. With no KEV entry, there is also no CISA required action or due date. The exclusively-hosted-service tag suggests that any fix would be applied by Microsoft on the service side rather than through a customer-installed patch. Check the MSRC advisory to confirm whether customers need to do anything.

Sources