LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-34327

CVE-2026-34327 - Vulnerability Analysis

HighCVSS: 8.2

Last Updated: May 8, 2026

Microsoft Partner Center - Open Redirect

Published: May 7, 2026Updated: May 8, 2026Remote Exploitable

Overview

Microsoft Partner Center contains an open redirect vulnerability caused by externally controlled references to resources in another sphere, letting unauthorized attackers perform network spoofing, exploit requires crafted URL.

Severity & Score

Severity: High
CVSS Score: 8.2

Impact

Unauthorized attackers can perform network spoofing, potentially leading to phishing or session hijacking.

Mitigation

Update to the latest version with the fix or apply vendor recommended patches.

Details

CVE ID
CVE-2026-34327
Severity
High
CVSS Score
8.2
Type
open_redirect
Status
confirmed

CWE

  • CWE-610

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N