CVE-2026-63508
10.0Microsoft · Planetary Computer Pro (GeoCatalog)
A missing authentication vulnerability for a critical function in Microsoft Planetary Computer Pro (GeoCatalog) allows an unauthorized attacker to elevate privileges over a network.
Executive summary
A critical authentication bypass in Microsoft Planetary Computer Pro allows unauthenticated remote attackers to elevate privileges, potentially leading to total system compromise.
Vulnerability
This vulnerability is caused by missing authentication for a critical function (CWE-306). An unauthenticated attacker can interact with the GeoCatalog component over a network to bypass authentication protocols and escalate privileges.
Business impact
The CVSS score of 10.0 underscores the severity of this flaw. By successfully exploiting this vulnerability, an attacker can gain unauthorized access to the system, leading to the potential loss of sensitive spatial data, unauthorized modification of records, and broader service disruption. Given the platform's role in data processing, this poses a substantial risk to information integrity.
Remediation
Immediate Action: Apply the August 2026 security update for Microsoft Planetary Computer Pro to address the authentication deficiency.
Proactive Monitoring: Review system access logs for unauthorized requests to the GeoCatalog function and monitor for any sudden changes in user privilege levels.
Compensating Controls: Utilize network-level access controls to restrict access to the GeoCatalog interface to authorized internal networks only until the patch is fully deployed.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the maximum severity rating, administrators must prioritize the immediate application of the August 2026 security update for all instances of Microsoft Planetary Computer Pro. Organizations should ensure that all systems are patched to eliminate the risk of unauthenticated privilege escalation.
More Microsoft CVEs all →
History
- Disclosed CVE record published
- Published in the daily brief critical section
- Analyst report written
- Fix documented per CVE record