Microsoft Fabric authentication bypass by spoofing
CVSS 10.0 authentication bypass in Microsoft Fabric. An unauthenticated remote attacker can spoof their identity to bypass authentication and elevate privileges over a network. Patched server-side by Microsoft.
- Vendor
- Microsoft
- Product
- Microsoft Fabric
- CVSS
- 10.0
- EPSS (exploit probability)
- 0.6%
- Status
- patched
- Published
CVE-2026-69843 is a CVSS 10.0 (critical) authentication bypass in Microsoft Fabric. An unauthenticated remote attacker can spoof their identity to bypass authentication and elevate privileges over a network. The attack vector is network-accessible; no authentication is required to exploit the flaw.
Microsoft Fabric is an integrated analytics and data platform consolidating Power BI, Data Factory, Synapse Analytics, and OneLake under a single tenant-based service. The spoofing-class bypass affects the platform’s authentication layer at the network perimeter.
Microsoft has patched the vulnerability server-side. No customer-side patch action is required to receive the fix. Organizations should review Fabric workspace access controls and audit logs for anomalous administrative activity from before the patch window, particularly service-principal role grants and workspace-level permission changes.
No exploitation in the wild has been confirmed as of the publication date. The CVE carries no CISA KEV designation.
Sources: MSRC advisory | NVD
