PT-2026-47974 · Microsoft · Exchange Server
CVSS v3.1
5.0
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Microsoft Exchange Server 2016 CU23
Microsoft Exchange Server 2019 CU14
Microsoft Exchange Server 2019 CU15
Microsoft Exchange Server SE
Description
Microsoft Exchange Server contains a Server-Side Request Forgery (SSRF) flaw, which occurs when a server fails to properly validate requests. This allows an authorized mailbox user to force the server to make HTTP requests to internal networks, enabling internal network reconnaissance and the disclosure of sensitive information from internal HTTP services. The issue stems from the fact that intranet address validation is gated on the
isBposUser variable, which is always false for on-premises installations, causing them to skip the security check entirely. Exploitation is achieved via a SOAP request to the EWS InstallApp endpoint using a crafted ManifestUrl parameter.Recommendations
Update Microsoft Exchange Server 2016 CU23 to the June 2026 SU.
Update Microsoft Exchange Server 2019 CU14 to the June 2026 SU.
Update Microsoft Exchange Server 2019 CU15 to the June 2026 SU.
Update Microsoft Exchange Server SE to the June 2026 SU.
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Exchange Server