Zum Inhalt

Bookings: Outside the lines until CVE-2026-54998

Microsoft Bookings had a serious authorization flaw: a low-privileged user (application) could act across tenant boundaries, turning a scheduling service into a privilege escalation path. CVE-2026-54998 was reported, fixed, and closed within 27 days.

Report Bookings
Number VULN-193275
Impact Elevation of Privilege
Cross tenant Yes
CVSS score CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Base score CVSS:3.1 8.8 / 7.7
CWE assigned CWE-863: Incorrect Authorization
CVE CVE-2026-54998
Fix applied Very Fast
From 5 Jun 2026
Until 2 Jul 2026 (27 days)

More about reporting a CVE: How to Report Security Vulnerabilities


Reference:

Kommentare