Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
10.0

CVE-2026-63508: Microsoft Planetary Computer Pro: Unauthorized Privilege Elevation

CVE-2026-63508 · published 28 days ago
Summary

A critical function in Microsoft Planetary Computer Pro is missing authentication, allowing an attacker with network access to gain elevated privileges without permission. This could lead to unauthorized changes or data access. To fix this, update Microsoft Planetary Computer Pro to the latest version or apply a security patch as soon as it's available.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
microsoft microsoft planetary computer pro (geocatalog) -
microsoft planetary_computer All versions
cpe:2.3:a:microsoft:planetary_computer:-:*:*:*:pro:*:*:*
Original advisory text
Microsoft Planetary Computer Pro Elevation of Privilege Vulnerability
Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network.
Severity
10.0 Critical
CVSS 3.1: 10.0 (NVD)
Exploitation
EPSS <1%
Type
CWE-306Missing Authentication for Critical Function
Timeline
Published6 Aug 2026
Updated3 Sep 2026
First seen7 Aug 2026
Sources
CVE-2026-63508 · MITRE
Monitor software like this
Free during beta