Skip to content
Critical Authentication Bypass Vulnerability Found in Microsoft Fabric

Critical Authentication Bypass Vulnerability Found in Microsoft Fabric

First seen 18 Sep 2026, 16:55 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 18, 2026 at 18:54 UTC

A critical authentication bypass vulnerability, CVE-2026-69843, has been discovered in Microsoft Fabric, allowing attackers to exploit the system without credentials or user interaction. This CVSS 10.0 vulnerability utilizes a network attack vector and has a scope-changed metric, enabling adversaries to breach security boundaries directly into the analytics and data tier where OneLake stores enterprise data. The vulnerability is classified under CWE-287 (Authentication Bypass by Spoofing) and poses significant risks as it impacts the data itself rather than just access controls. This incident marks the fifth authentication-bypass vulnerability identified in Microsoft services since September 1, 2026, highlighting a concerning trend in the company's security posture. Other related vulnerabilities include CVE-2026-77903 in Microsoft Dataverse, which was published just a day earlier. The vulnerabilities span various Microsoft services, including Azure AD and Azure AI, indicating a widening attack surface. The current status of CVE-2026-69843 is that it has been disclosed but is not yet confirmed to be actively exploited.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-03
CVE-2026-83711 published
Azure AD B2C Authorization Bypass Through User-Controlled Key disclosed with CVSS 10.0.
Tech.Yahoo
2026-09-03
CVE-2026-70352 published
Azure AI Language Missing Authentication for Critical Function disclosed with CVSS 10.0.
Tech.Yahoo
2026-09-08
CVE-2026-83941 published
Entra ID Elevation of Privilege vulnerability disclosed with CVSS 9.9.
Tech.Yahoo
2026-09-17
CVE-2026-62874 published
CVE-2026-77903, an authentication bypass in Microsoft Dataverse, disclosed with CVSS 9.0.
Tech.Yahoo
2026-09-17
CVE-2026-69843 published
Critical authentication bypass vulnerability in Microsoft Fabric disclosed with CVSS 10.0.
Tech.Yahoo
2026-09-17
CVE-2026-77903 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE

More articles in this cluster (3)

Following this threat?

Track CVE-2026-62874 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed