Analysis of the CVE-2026-45504 vulnerability in Microsoft Exchange that allows reading arbitrary files

The article examines the CVE-2026-45504 vulnerability, which affects Microsoft Exchange Server. Researchers demonstrated that even a low-privileged user can gain access to arbitrary files on the server via an SSRF chain by exploiting improper URL scheme validation.
The attack is based on manipulating the WebApplicationUrl and using the "#" fragment, which allows bypassing appended parameters and forcing the server to read local files. As a result, an attacker can extract sensitive data.
Vulnerabilities
9.0
CVE-2026-45504
Vendors
Microsoft
Products
Microsoft Exchange
Microsoft Exchange Server