PT-2026-24328 · Microsoft · Azure Mcp Server

·

CVE-2026-26118

·

Published

2026-03-10

·

Updated

2026-07-13

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Azure MCP Server (affected versions not specified)
Description An authorized attacker can exploit a server-side request forgery (SSRF) condition in Azure MCP Server to gain elevated privileges on a network. SSRF occurs when an application makes requests to an unintended location, potentially allowing an attacker to access sensitive resources or perform actions on behalf of the server.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

LPE

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-03055
CVE-2026-26118
GHSA-HHFX-WFVQ-7G9C
PYSEC-2026-2669

Affected Products

Azure Mcp Server