Information Disclosure Vulnerability in Azure DevOps by Microsoft
CVE-2026-42826

10CRITICAL

Key Information:

Vendor

Microsoft

Vendor
CVE Published:
7 May 2026

What is CVE-2026-42826?

An information disclosure vulnerability exists in Azure DevOps that may allow an unauthorized actor to access sensitive information over a network. This breach could potentially expose users’ confidential data, making it crucial for organizations to take immediate action to mitigate such risks. Implementing recommended security measures, including applying security updates provided by Microsoft, can significantly help in protecting sensitive information against unauthorized access.

Affected Version(s)

Azure DevOps -

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.