PT-2026-24328 · Microsoft · Azure Mcp Server
Daniel Santos
·
Published
2026-03-10
·
Updated
2026-04-22
·
CVE-2026-26118
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Azure MCP Server (affected versions not specified)
Description
An authorized attacker can exploit a server-side request forgery (SSRF) condition in Azure MCP Server to gain elevated privileges on a network. SSRF occurs when an application makes requests to an unintended location, potentially allowing an attacker to access sensitive resources or perform actions on behalf of the server.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
LPE
RCE
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Azure Mcp Server