CVE-2026-63508
Microsoft · Planetary Computer Pro (GeoCatalog)
Missing authentication for a critical function in Microsoft Planetary Computer Pro (GeoCatalog) allows an unauthorized attacker to elevate privileges over a network.
Executive summary
A critical authentication bypass in Microsoft Planetary Computer Pro (GeoCatalog) allows remote, unauthenticated attackers to elevate privileges.
Vulnerability
This vulnerability is a CWE-306: Missing Authentication for Critical Function flaw. It permits an unauthenticated attacker to access restricted administrative functions, facilitating privilege escalation across the network.
Business impact
The CVSS score of 10.0 indicates a critical risk profile. An attacker exploiting this vulnerability could gain unauthorized control over the GeoCatalog service, potentially compromising the integrity of geospatial data or manipulating system configurations. The ease of exploitation via remote network vectors mandates immediate attention to prevent unauthorized administrative access.
Remediation
Immediate Action: Consult the Microsoft Security Response Center (MSRC) advisory to identify and apply the latest security updates for Planetary Computer Pro.
Proactive Monitoring: Monitor application access logs for irregular authentication patterns or unauthorized access to administrative endpoints.
Compensating Controls: Implement strict network-level segmentation to restrict access to the GeoCatalog service to authorized personnel only.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Due to the critical CVSS score and the nature of the flaw, administrators should prioritize applying vendor patches as soon as they become available. Protecting administrative functions from unauthenticated access is essential to maintaining the security posture of the affected platform.