CVE-2026-26118
EUVD-2026-1068910.03.2026, 18:18
Server-side request forgery (ssrf) in Azure MCP Server allows an authorized attacker to elevate privileges over a network.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| microsoft | azure_mcp_server | 𝑥 < 2.0.0 |
| microsoft | azure_mcp_server | 2.0.0:beta1 |
| microsoft | azure_mcp_server | 2.0.0:beta10 |
| microsoft | azure_mcp_server | 2.0.0:beta11 |
| microsoft | azure_mcp_server | 2.0.0:beta12 |
| microsoft | azure_mcp_server | 2.0.0:beta13 |
| microsoft | azure_mcp_server | 2.0.0:beta14 |
| microsoft | azure_mcp_server | 2.0.0:beta15 |
| microsoft | azure_mcp_server | 2.0.0:beta16 |
| microsoft | azure_mcp_server | 2.0.0:beta2 |
| microsoft | azure_mcp_server | 2.0.0:beta3 |
| microsoft | azure_mcp_server | 2.0.0:beta4 |
| microsoft | azure_mcp_server | 2.0.0:beta5 |
| microsoft | azure_mcp_server | 2.0.0:beta6 |
| microsoft | azure_mcp_server | 2.0.0:beta7 |
| microsoft | azure_mcp_server | 2.0.0:beta8 |
| microsoft | azure_mcp_server | 2.0.0:beta9 |
𝑥
= Vulnerable software versions