{"id":"CVE-2026-26118","aliases":["GHSA-hhfx-wfvq-7g9c","PYSEC-2026-2669"],"title":"Azure MCP Server has Server-Side Request Forgery issue that allows authorized attacker to elevate privileges over a network","summary":"Azure MCP Server has Server-Side Request Forgery issue that allows authorized attacker to elevate privileges over a network","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","vendor":"Azure","product":"Azure.Mcp","ecosystem":"nuget","affected":["Azure.Mcp >= 2.0.0-beta.1, < 2.0.0-beta.17","Azure.Mcp >= 1.0.0, < 1.0.2","@azure/mcp >= 2.0.0-beta.1, < 2.0.0-beta.17","msmcp-azure >= 2.0.0b14, < 2.0.0b17","@azure/mcp >= 1.0.0, < 1.0.2"],"patched":["Azure.Mcp 2.0.0-beta.17","Azure.Mcp 1.0.2","@azure/mcp 2.0.0-beta.17","msmcp-azure 2.0.0b17","@azure/mcp 1.0.2"],"published":"2026-03-10","updated":"2026-09-10","sourceUpdated":"2026-09-10T03:50:39.818542295Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-hhfx-wfvq-7g9c","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-26118"},{"url":"https://github.com/microsoft/mcp/commit/804ff60293206c4d8e832f772097238561bf2c34"},{"url":"https://github.com/microsoft/mcp"},{"url":"https://github.com/microsoft/mcp/releases/tag/Azure.Mcp.Server-1.0.2"},{"url":"https://github.com/microsoft/mcp/releases/tag/Azure.Mcp.Server-2.0.0-beta.17"},{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26118"}],"tags":["osv","nuget","exploit-available"],"epss":0.00959,"epssPercentile":0.60045,"exploits":{"github":1,"githubRepos":["https://github.com/j-dahl7/mcp-attack-detection-sentinel"],"checkedAt":"2026-09-24T07:53:01.271Z"},"exploitAvailable":true,"ingestedAt":"2026-07-13T18:57:59.214Z","slug":"CVE-2026-26118","body":"## Overview\n\nServer-Side Request Forgery (SSRF) in Azure MCP Server allows an authorized attacker to elevate privileges over a network.\n\n## Affected packages\n\n- `Azure.Mcp >= 2.0.0-beta.1, < 2.0.0-beta.17`\n- `Azure.Mcp >= 1.0.0, < 1.0.2`\n- `@azure/mcp >= 2.0.0-beta.1, < 2.0.0-beta.17`\n- `msmcp-azure >= 2.0.0b14, < 2.0.0b17`\n- `@azure/mcp >= 1.0.0, < 1.0.2`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `Azure.Mcp 2.0.0-beta.17`\n- `Azure.Mcp 1.0.2`\n- `@azure/mcp 2.0.0-beta.17`\n- `msmcp-azure 2.0.0b17`\n- `@azure/mcp 1.0.2`","depth":"midnight","depthScore":61,"depthScoreParts":{"impact":48.4,"likelihood":0.2,"exploitation":12,"ransomware":0},"changes":[{"seq":5044,"id":"CVE-2026-26118","ts":1788887230333,"field":"exploit_available","old":"false","new":"true"},{"seq":3927,"id":"CVE-2026-26118","ts":1788886361091,"field":"exploit_available","old":"true","new":"false"},{"seq":2749,"id":"CVE-2026-26118","ts":1788883027843,"field":"exploit_available","old":"false","new":"true"},{"seq":1778,"id":"CVE-2026-26118","ts":1788882430844,"field":"exploit_available","old":"true","new":"false"},{"seq":884,"id":"CVE-2026-26118","ts":1788881864126,"field":"exploit_available","old":"false","new":"true"}]}