Microsoft Fabric Vulnerability Expands Identity Attack Surface
A recent vulnerability in Microsoft Fabric's authentication system has highlighted the expanding identity attack surface. The issue, CVE-2026-69843, is a CVSS 10.0 unauthenticated bypass by spoofing that allows attackers to exploit it without credentials or user interaction.
Since September 1, there have been five Microsoft authentication flaws, including this one, affecting the control plane, AI services, and now the data and analytics tier. The vulnerability is classified as CWE-287 (Authentication Bypass by Spoofing) and has a CVSS vector of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H.
Fabric is a unified SaaS analytics platform that consolidates end-to-end data workflows, including ingestion, transformation, real-time processing, analytics, and reporting. The platform holds the actual enterprise data, making it a high-risk target for attackers.
Microsoft has addressed these vulnerabilities through server-side fixes, requiring no action from customers.