CVE-2026-94510

Microsoft Bookings

Published 8 Oct 2026 · updated 9 Oct 2026 · Awaiting Analysis

9.9 Critical · CVSS 3.1, microsoft.com

Description

Authorization bypass through user-controlled key in Microsoft Bookings allows an unauthorized attacker to elevate privileges over a network.

References