Microsoft Exchange Vulnerability Allows Privilege Escalation via Authentication Bypass
A critical vulnerability in Microsoft Exchange, identified as ZDI-26-538 (CVE-2026-62911), allows remote attackers to escalate privileges by bypassing authentication mechanisms.

The Zero Day Initiative has disclosed a critical vulnerability, ZDI-26-538, affecting Microsoft Exchange Server. This flaw, assigned the identifier CVE-2026-62911, permits remote attackers to escalate their privileges on compromised systems.
The vulnerability stems from an improper authorization flaw within the handling of authorization requests. Specifically, the issue lies in the inadequate management of user sessions, which attackers can exploit. While an attacker must first authenticate to the system, the vulnerability allows them to bypass these existing authentication controls, effectively gaining elevated access.
Successful exploitation of this vulnerability could lead to the execution of arbitrary code with SYSTEM-level privileges. This level of access is highly coveted by attackers as it grants complete control over the affected server, enabling them to deploy malware, exfiltrate sensitive data, or further compromise the network.
The Zero Day Initiative has assigned a CVSS score of 8.8 to this vulnerability, classifying it as critical. This high score reflects the potential impact and ease of exploitation, particularly when combined with other vulnerabilities that might grant initial access or bypass other security measures.
Microsoft has acknowledged the vulnerability and released an update to address it. Users are strongly advised to apply the security patch provided by Microsoft to mitigate the risk of exploitation. Further details on the patch can be found on Microsoft's security update guide.
The vulnerability was discovered by Orange Tsai of the DEVCORE Research Team. The Zero Day Initiative coordinated the public disclosure of this advisory on August 11, 2026, following the initial report to the vendor on May 21, 2026.
This vulnerability highlights the ongoing challenges in securing complex enterprise software like Microsoft Exchange. Even with authentication mechanisms in place, flaws in authorization logic and session management can create significant security gaps. Organizations must remain vigilant in applying security updates promptly to protect against such threats.
As privilege escalation vulnerabilities continue to be a primary objective for threat actors, patching and robust access control measures are paramount. The exploitation of such flaws can have cascading effects, leading to widespread compromise if not addressed swiftly.
This advisory from the Zero Day Initiative provides further technical details on the Microsoft Exchange authentication bypass vulnerability, identified as CVE-2026-62911. It highlights that the flaw allows remote attackers to exploit a weak authentication path without requiring any prior authentication. The vulnerability was discovered by Orange Tsai of DEVCORE Research Team and has been assigned a CVSS score of 8.1.
This Zero Day Initiative advisory (ZDI-26-535) details a Microsoft Exchange vulnerability that allows for remote code execution. While the previously disclosed ZDI-26-538 also covered an authentication bypass in Exchange leading to privilege escalation, this new advisory specifically highlights an external control of file path vulnerability. The flaw, CVE-2026-62911, requires authentication but permits bypassing it to achieve SYSTEM-level code execution, differing from the privilege escalation focus of ZDI-26-538.