PT-2026-24328 · Microsoft · Azure Mcp Server

Daniel Santos

·

Published

2026-03-10

·

Updated

2026-04-22

·

CVE-2026-26118

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Azure MCP Server (affected versions not specified)
Description An authorized attacker can exploit a server-side request forgery (SSRF) condition in Azure MCP Server to gain elevated privileges on a network. SSRF occurs when an application makes requests to an unintended location, potentially allowing an attacker to access sensitive resources or perform actions on behalf of the server.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

RCE

SSRF

Weakness Enumeration

Related Identifiers

BDU:2026-03055
CVE-2026-26118
GHSA-HHFX-WFVQ-7G9C

Affected Products

Azure Mcp Server