Bookings: Outside the lines until CVE-2026-54998
Microsoft Bookings had a serious authorization flaw: a low-privileged user (application) could act across tenant boundaries, turning a scheduling service into a privilege escalation path. CVE-2026-54998 was reported, fixed, and closed within 27 days.
| Report | Bookings |
|---|---|
| Number | VULN-193275 |
| Impact | Elevation of Privilege |
| Cross tenant | Yes |
| CVSS score | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C |
| Base score | CVSS:3.1 8.8 / 7.7 |
| CWE assigned | CWE-863: Incorrect Authorization |
| CVE | CVE-2026-54998 |
| Fix applied | Very Fast |
| From | 5 Jun 2026 |
| Until | 2 Jul 2026 (27 days) |
More about reporting a CVE: How to Report Security Vulnerabilities
Reference:
- Microsoft Bookings
- CVE Program Mission - Exchange Online
- CVE-2026-54998 - msrc
- CVE-2026-54998 - nvd.nist.gov
- CVE-2026-54998 - cve.mitre.org
- CVE-2026-54998 - cve.org
- CVE-2026-54998 - cvedetails