{"id":"GHSA-hhfx-wfvq-7g9c","summary":"Azure MCP Server has Server-Side Request Forgery issue that allows authorized attacker to elevate privileges over a network","details":"Server-Side Request Forgery (SSRF) in Azure MCP Server allows an authorized attacker to elevate privileges over a network.","aliases":["CVE-2026-26118","PYSEC-2026-2669"],"modified":"2026-09-10T03:50:39.818542295Z","published":"2026-03-10T18:31:21Z","database_specific":{"cwe_ids":["CWE-918"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-03-11T19:59:54Z","nvd_published_at":"2026-03-10T18:18:41Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-26118"},{"type":"WEB","url":"https://github.com/microsoft/mcp/commit/804ff60293206c4d8e832f772097238561bf2c34"},{"type":"PACKAGE","url":"https://github.com/microsoft/mcp"},{"type":"WEB","url":"https://github.com/microsoft/mcp/releases/tag/Azure.Mcp.Server-1.0.2"},{"type":"WEB","url":"https://github.com/microsoft/mcp/releases/tag/Azure.Mcp.Server-2.0.0-beta.17"},{"type":"WEB","url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26118"}],"affected":[{"package":{"name":"Azure.Mcp","ecosystem":"NuGet","purl":"pkg:nuget/Azure.Mcp"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.0.0-beta.1"},{"fixed":"2.0.0-beta.17"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-hhfx-wfvq-7g9c/GHSA-hhfx-wfvq-7g9c.json"}},{"package":{"name":"Azure.Mcp","ecosystem":"NuGet","purl":"pkg:nuget/Azure.Mcp"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.0.0"},{"fixed":"1.0.2"}]}],"versions":["1.0.0","1.0.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-hhfx-wfvq-7g9c/GHSA-hhfx-wfvq-7g9c.json"}},{"package":{"name":"@azure/mcp","ecosystem":"npm","purl":"pkg:npm/%40azure/mcp"},"ranges":[{"type":"SEMVER","events":[{"introduced":"2.0.0-beta.1"},{"fixed":"2.0.0-beta.17"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-hhfx-wfvq-7g9c/GHSA-hhfx-wfvq-7g9c.json"}},{"package":{"name":"msmcp-azure","ecosystem":"PyPI","purl":"pkg:pypi/msmcp-azure"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.0.0b14"},{"fixed":"2.0.0b17"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-hhfx-wfvq-7g9c/GHSA-hhfx-wfvq-7g9c.json"}},{"package":{"name":"@azure/mcp","ecosystem":"npm","purl":"pkg:npm/%40azure/mcp"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.0.0"},{"fixed":"1.0.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-hhfx-wfvq-7g9c/GHSA-hhfx-wfvq-7g9c.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}