Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-hhfx-wfvq-7g9c | Azure MCP Server has Server-Side Request Forgery issue that allows authorized attacker to elevate privileges over a network |
Fri, 20 Mar 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Microsoft azure Mcp Server Tools 1
Microsoft azure Mcp Server Tools 2 |
|
| CPEs | cpe:2.3:a:microsoft:azure_mcp_server_tools_1:*:*:*:*:*:*:*:* cpe:2.3:a:microsoft:azure_mcp_server_tools_2:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Microsoft azure Mcp Server Tools 1
Microsoft azure Mcp Server Tools 2 |
Fri, 13 Mar 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Microsoft azure Mcp Server
|
|
| CPEs | cpe:2.3:a:microsoft:azure_mcp_server:*:*:*:*:*:*:*:* cpe:2.3:a:microsoft:azure_mcp_server:2.0.0:beta10:*:*:*:*:*:* cpe:2.3:a:microsoft:azure_mcp_server:2.0.0:beta11:*:*:*:*:*:* cpe:2.3:a:microsoft:azure_mcp_server:2.0.0:beta12:*:*:*:*:*:* cpe:2.3:a:microsoft:azure_mcp_server:2.0.0:beta13:*:*:*:*:*:* cpe:2.3:a:microsoft:azure_mcp_server:2.0.0:beta14:*:*:*:*:*:* cpe:2.3:a:microsoft:azure_mcp_server:2.0.0:beta15:*:*:*:*:*:* cpe:2.3:a:microsoft:azure_mcp_server:2.0.0:beta16:*:*:*:*:*:* cpe:2.3:a:microsoft:azure_mcp_server:2.0.0:beta1:*:*:*:*:*:* cpe:2.3:a:microsoft:azure_mcp_server:2.0.0:beta2:*:*:*:*:*:* cpe:2.3:a:microsoft:azure_mcp_server:2.0.0:beta3:*:*:*:*:*:* cpe:2.3:a:microsoft:azure_mcp_server:2.0.0:beta4:*:*:*:*:*:* cpe:2.3:a:microsoft:azure_mcp_server:2.0.0:beta5:*:*:*:*:*:* cpe:2.3:a:microsoft:azure_mcp_server:2.0.0:beta6:*:*:*:*:*:* cpe:2.3:a:microsoft:azure_mcp_server:2.0.0:beta7:*:*:*:*:*:* cpe:2.3:a:microsoft:azure_mcp_server:2.0.0:beta8:*:*:*:*:*:* cpe:2.3:a:microsoft:azure_mcp_server:2.0.0:beta9:*:*:*:*:*:* |
|
| Vendors & Products |
Microsoft azure Mcp Server
|
Tue, 10 Mar 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 10 Mar 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Server-side request forgery (ssrf) in Azure MCP Server allows an authorized attacker to elevate privileges over a network. | |
| Title | Azure MCP Server Tools Elevation of Privilege Vulnerability | |
| First Time appeared |
Microsoft
Microsoft azure Mcp Server Tools |
|
| Weaknesses | CWE-918 | |
| CPEs | cpe:2.3:a:microsoft:azure_mcp_server_tools:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Microsoft
Microsoft azure Mcp Server Tools |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: microsoft
Published:
Updated: 2026-04-14T16:36:40.631Z
Reserved: 2026-02-11T15:52:13.911Z
Link: CVE-2026-26118
Updated: 2026-03-10T19:50:08.517Z
Status : Analyzed
Published: 2026-03-10T18:18:41.180
Modified: 2026-03-13T20:12:47.740
Link: CVE-2026-26118
No data.
OpenCVE Enrichment
Updated: 2026-03-23T09:55:35Z
Github GHSA