← Back to overview

CVE-2026-63509 describes a relative path traversal vulnerability in Microsoft Fabric. The flaw allows an authorized attacker to elevate privileges over a network. The vulnerability requires the attacker to already have some level of authorization within the environment. Privilege escalation vulnerabilities in cloud and data platform services like Microsoft Fabric can have significant impact on enterprise environments. Microsoft has published an advisory through the Microsoft Security Response Center (MSRC). The vulnerability is tracked in the National Vulnerability Database (NVD) at NIST. No additional technical details or proof-of-concept exploits are referenced in the current disclosure. Organizations using Microsoft Fabric should monitor for patches and apply mitigations as directed by Microsoft.

Affected products

  • Microsoft Fabric

Related CVE's

  • CVE-2026-63509

Categories

  • Cloud & Virtualization
  • Enterprise Applications
  • Identity & Access