ZDI-26-538: (Pwn2Own) Microsoft Exchange Improper Authorization Privilege Escalation Vulnerability
Admiralty grading (A–F · 1–6)
Source reliability
- A Completely reliable
- B Usually reliable
- C Fairly reliable
- D Not usually reliable
- E Unreliable
- F Cannot be judged
Information credibility
- 1 Confirmed
- 2 Probably true
- 3 Possibly true
- 4 Doubtful
- 5 Improbable
- 6 Cannot be judged
NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.
Key metrics
- CVSS
- 8.0
- EPSS
- 1%
Affected versions
Key insight
The flaw was demonstrated at Pwn2Own; it allows bypassing the existing authentication mechanism and thereby escalating privileges on Exchange servers, despite authentication being nominally required.
Description
The Zero Day Initiative has published vulnerability CVE-2026-62911 in Microsoft Exchange with a CVSS rating of 8.8; it was demonstrated during the Pwn2Own competition. Remote attackers can escalate privileges on affected Exchange installations. Although authentication is required for exploitation, the existing authentication mechanism can be bypassed, significantly lowering the bar for an attack. At the time of publication there is no information on exploitation in the wild or on inclusion in the CISA KEV list, and no public exploit code has been confirmed.
Risk score
- cvss base
- 80.00
- kev bonus
- 0.00
- epss bonus
- 0.00
- poc bonus
- 15.00
- raw before weight
- 95.00
- industry weight
- 1.21
- freshness factor
- 0.50
- exploitability factor
- 1.00
- days old
- 31.00
- vendor mismatch penalty
- 0.00
Path: operational