External risk intelligence

Microsoft Bookings Authorization Bypass Allows Privilege Escalation

CVE advisorySeverity: CRITICAL (CVSS 9.9)

CVE-2026-94510

Microsoft Bookings is a web-based application integrated into Microsoft 365, commonly used as a public-facing scheduling service accessible via the internet. As a cloud-hosted web application, it is designed to be reachable by external users for booking appointments, making the attack surface typically exposed to the internet.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

An authorization bypass vulnerability has been identified in Microsoft Bookings, a web-based scheduling service. This issue could allow an attacker to gain elevated privileges over a network without proper authorization. The primary concern is to confirm if this technology is in use and if it is exposed externally, as this could present a significant risk if exploited.

  • Unauthorized access can bypass security controls.
  • Understand potential for unauthorized privilege escalation.
  • Confirm relevance and scope of affected systems.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending a specially crafted request to Microsoft Bookings. This request would take advantage of how the application handles user-provided keys, allowing an unauthenticated attacker to bypass authorization checks. Successfully exploiting this could lead to an attacker gaining elevated privileges within the system over a network.

  • No authentication required to initiate attack.
  • Triggered by sending a malicious request.
  • Risk of unauthorized privilege escalation.

Live Threat

Current exploitation, exposure, and threat context

An unauthorized attacker could bypass authorization controls in Microsoft Bookings over a network to gain elevated privileges. This could affect the service's ability to manage user access and appointment data.

  • Unauthorized privilege escalation.
  • Network access bypasses authentication.
  • Service access and data manipulation.

Operational Fix

Recommended remediation, mitigation, and detection steps

The critical authorization bypass vulnerability in Microsoft Bookings, accessible over the network, requires immediate attention from teams managing Microsoft 365 environments and cloud-hosted applications. The first practical step is to identify all instances of Microsoft Bookings, confirm their internet reachability and business criticality, and then assign ownership for remediation planning based on the assessed risk.

  • Ownership: Cloud Platform and M365 administrators.
  • Verify first: Internet reachability and business criticality.
  • Action: Plan and coordinate secure remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Microsoft Bookings?

Microsoft Bookings is a web-based scheduling application integrated into the Microsoft 365 suite. It enables organizations to manage appointments, staff availability, and customer bookings through a public-facing interface. Because it is part of the cloud-hosted Microsoft 365 ecosystem, it is designed to facilitate external interactions, allowing users to coordinate meetings without requiring a direct account within the hosting organization's internal directory.

How does this authorization bypass work in CVE-2026-94510?

This vulnerability is classified as CWE-639, or Authorization Bypass Through User-Controlled Key. Essentially, the application incorrectly validates or trusts specific keys provided by a user during a request. An attacker can manipulate these keys to trick the system into granting them permissions they should not have. In the context of this CVE, this flaw allows an unauthenticated actor to bypass standard security checks and gain elevated privileges within the service.

Do I need to be authenticated to trigger CVE-2026-94510?

No, authentication is not a prerequisite to trigger this vulnerability. An attacker can initiate the exploit by sending a specially crafted request to the Microsoft Bookings service over the network. It is important to note that this is not triggered by standard, legitimate user activity like booking an appointment; it requires a malicious, intentionally malformed request designed to exploit how the application handles authorization keys.

Why should I care about this vulnerability?

According to Halo Surface Signal, Microsoft Bookings is typically a public-facing service meant to be reached by users over the internet. This design means that instances of the application are often exposed to external, unauthenticated traffic by default. Because the vulnerability allows for privilege escalation, it represents a significant risk to the integrity of appointment data and access controls within your Microsoft 365 environment.

Is there a first step to take for CVE-2026-94510?

Your first priority is to locate all instances of Microsoft Bookings currently in use within your organization. Once identified, confirm the reachability of these instances—specifically checking which are accessible via the internet—and determine their overall business criticality. This information allows you to map out which environments require the most urgent attention and helps your Microsoft 365 administrators coordinate a remediation plan.

References