CVE-2026-94510 is a critical (CVSS 9.9) authorization bypass flaw in Microsoft Bookings that lets an unauthorized attacker elevate privileges over a network.
What Is It
Microsoft describes CVE-2026-94510 as an "authorization bypass through user-controlled key" in Microsoft Bookings. It is classified as CWE-639 (Authorization Bypass Through User-Controlled Key). This class of flaw occurs when an application uses a value the user can change to decide what data or functions they may access. The result is privilege escalation over a network.
Microsoft ([email protected]) published the record to NVD on 2026-10-08. Its NVD status is currently "Received," so NVD has not yet completed its own analysis.
Why It Matters
Microsoft rates the flaw 9.9 CRITICAL under CVSS 3.1, with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:L:
- Network-reachable with low attack complexity
- No privileges and no user interaction required
- Scope changed, so the impact can extend beyond the vulnerable component
- High integrity impact, with low confidentiality and availability impact
An unauthenticated attacker who can reach the service could exploit it with little effort. The exploitability subscore is 3.9 and the impact subscore is 5.3.
Exploitation status: The supplied data contains no CISA Known Exploited Vulnerabilities (KEV) entry for this CVE. KEV does not currently confirm active exploitation, and the supplied sources contain no other evidence of exploitation.
What's Vulnerable
- Vendor: Microsoft
- Product: Microsoft Bookings
- Versions: Listed as "-" (no specific version range given), status "affected"
Microsoft has tagged the CVE exclusively-hosted-service, which means Microsoft Bookings runs as a Microsoft-hosted service rather than as software customers install themselves. The record lists no CPE entries.
Patch Status
The supplied sources give no specific remediation steps or required customer actions. With no KEV entry, there is also no CISA required action or due date. The exclusively-hosted-service tag suggests that any fix would be applied by Microsoft on the service side rather than through a customer-installed patch. Check the MSRC advisory to confirm whether customers need to do anything.