CVE-2026-26118
Server-Side Request Forgery (SSRF) in Azure MCP Server allows an authorized attacker to elevate privileges over a network.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://nvd.nist.gov/vuln/detail/CVE-2026-26118, https://github.com/microsoft/mcp/commit/804ff60293206c4d8e832f772097238561bf2c34, https://github.com/microsoft/mcp, https://github.com/microsoft/mcp/releases/tag/Azure.Mcp.Server-1.0.2, https://github.com/microsoft/mcp/releases/tag/Azure.Mcp.Server-2.0.0-beta.17, https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26118
