
CVE-2026-54998 RCE Exploit
DISCLAIMER
This repository is for educational and research purposes only.
The author is not responsible for any misuse, damage, or illegal activities caused by the use of this material.
Use at your own risk. Respect applicable laws and ethical guidelines.
CVE-2026-54998 is an Incorrect Authorization vulnerability (CWE-863) in Microsoft Exchange Online. It allows an authenticated attacker with low-level user privileges to elevate their access rights beyond the intended authorization scope over the network.
The vulnerability was published on July 3, 2026. CVSS v3.1 score: 8.8 (High).
Patch Available: Yes (released July 3, 2026 via GitHub Advisory GHSA-phr2-vr74-whpx).
The root cause is improper authorization checks in Exchange Online. An authenticated user with standard/low privileges can manipulate requests to gain higher-level permissions, allowing actions beyond their assigned scope (e.g., accessing other users' mailboxes, administrative functions, etc.).
Exploit - href