
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-26118 is a Server-Side Request Forgery (SSRF) vulnerability in Microsoft's Azure MCP Server that allows an authenticated attacker to elevate privileges over a network. The vulnerability affects Azure MCP Server versions prior to 2.0.0, including all beta releases from beta1 through beta16. It was disclosed and patched on March 10, 2026, as part of Microsoft's March 2026 Patch Tuesday security update cycle. The vulnerability carries a CVSS v3.1 base score of 8.8 (High) (MSRC Advisory, Feedly).
The root cause is classified as CWE-918 (Server-Side Request Forgery), where the Azure MCP Server fails to adequately validate or restrict outbound requests it generates on behalf of authenticated users. An attacker with low-level network access and valid credentials can craft malicious requests that cause the server to forward forged requests to internal services or resources that would otherwise be inaccessible, effectively bypassing access controls. The attack requires no user interaction and has low attack complexity, making it straightforward to execute once an attacker has authenticated access. A security scanner tool (mcp-check) and visual proof-of-concept audit materials have been published publicly, though no weaponized exploit has been confirmed (MSRC Advisory, mcp-check GitHub, PageBolt Blog).
Successful exploitation allows an authenticated attacker to forge server-side requests to internal Azure services and resources, achieving privilege escalation beyond their authorized access level. The CVSS scoring reflects high impacts across confidentiality, integrity, and availability, meaning an attacker could potentially read sensitive internal data, modify resources, and disrupt service availability. The SSRF vector is particularly dangerous in cloud environments like Azure, where internal metadata services, storage endpoints, and management APIs may be reachable from the MCP Server's network context, enabling lateral movement to higher-privilege Azure resources (MSRC Advisory, Feedly).
As of the time of reporting, there is no confirmed in-the-wild exploitation of CVE-2026-26118, and no weaponized exploit code has been identified. A TypeScript-based MCP security scanner tool (mcp-check) exists on GitHub that detects the presence of vulnerability classes in MCP servers but does not actively exploit them; visual proof-of-concept audit materials have also been published (mcp-check GitHub, PageBolt Blog). The EPSS score is approximately 0.057%, indicating a low probability of exploitation in the near term. The vulnerability is not currently listed in CISA's Known Exploited Vulnerabilities (KEV) catalog. Qualys has added detection for this vulnerability (detection ID: 5009014) (Feedly).
http://169.254.169.254/, internal storage endpoints, or management APIs).169.254.169.254) or unexpected internal IP ranges; unusual requests to Azure management APIs (management.azure.com) originating from the MCP Server host.Microsoft released a patch on March 10, 2026; organizations should update Azure MCP Server to version 2.0.0 or later, which resolves the SSRF vulnerability. As interim mitigations, restrict network access to Azure MCP Server instances to only authorized users and services, and implement network segmentation to limit the server's ability to reach sensitive internal endpoints. Monitoring authentication logs for suspicious activity from authenticated users and blocking outbound requests from the MCP Server to internal metadata services (e.g., 169.254.169.254) at the network level can reduce exposure. Qualys detection ID 5009014 can be used to identify vulnerable instances (MSRC Advisory, Feedly).
CVE-2026-26118 received coverage as part of the broader March 2026 Patch Tuesday reporting, with security outlets including Tenable, Rapid7, Sophos, Cisco Talos, and Zero Day Initiative covering the overall patch batch (Tenable Blog, Rapid7 Blog, Sophos Blog). The vulnerability attracted specific attention from the MCP security research community, with a developer publishing an audit of Microsoft's MCP servers claiming to have found 20 vulnerabilities, and OWASP referencing MCP security issues in their AI Security Verification Standard (AISVS) project (Dev.to Audit). Community discussion on Reddit noted a broader trend of CVEs being filed against MCP servers, reflecting growing security scrutiny of the MCP ecosystem. Security Today highlighted the vulnerability in the context of "shadow AI" threats, underscoring industry concern about AI infrastructure security.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."