The National Vulnerability Database has published three CRITICAL-rated, network-vector vulnerabilities across Microsoft's cloud service portfolio within a 72-hour window — and the headline entry, CVE-2026-96207, carries a perfect CVSS 10.0. In my fifteen years of incident response, a 10.0 on a network-reachable, no-authentication-required privilege-escalation path into a partner administration plane is about as bad as the scoring system allows. Partner Center is the control plane through which CSPs and managed providers administer downstream customer tenants; a compromise there does not stop at one organization — it propagates across every tenant the partner relationship touches.
The three CVEs defenders need on their radar right now:
- CVE-2026-96207 (CVSS 10.0) — Improper certificate validation in Microsoft Partner Center allows an unauthorized attacker to elevate privileges over the network.
- CVE-2026-94510 (CVSS 9.9) — Authorization bypass through a user-controlled key in Microsoft Bookings allows an unauthorized attacker to access resources across tenant boundaries.
- CVE-2026-88131 (CVSS 9.8) — Deserialization of untrusted data in Microsoft Dataverse allows an unauthorized attacker to execute code.
Because all three affect Microsoft-operated cloud services, the patching burden is largely on Microsoft — but do not let that lull you into passivity. Server-side fixes do not retroactively tell you whether you were exploited before remediation, and post-compromise artifacts (rogue service principals, illicit consent grants, anomalous Dataverse plugin executions) persist after the hole is closed. Your job now is hunting for pre-patch exploitation and hardening against follow-on abuse.
Technical Analysis
CVE-2026-96207 — Partner Center: Improper Certificate Validation (CVSS 10.0)
CWE-295 (Improper Certificate Validation) in the Partner Center service means the TLS/certificate trust decision that gates privileged operations can be subverted by an attacker who does not hold valid credentials. Practically, this class of flaw enables scenarios such as: presenting a forged or mis-issued certificate that the service improperly accepts as a trusted partner identity, or exploiting a validation gap (missing chain-of-trust enforcement, absent revocation checking, or hostname/SAN mismatches not enforced) to impersonate an authorized partner integration.
Why a 10.0 is credible here: Partner Center credentials and partner-level service principals frequently hold Admin Agent / GDAP (Granular Delegated Admin Privileges) relationships into dozens or hundreds of customer tenants. A successful elevation of privilege at this layer is a supply-chain event — the attacker inherits delegated administrative access downstream. Exploitation is network-based (AV:N), low complexity (AC:L), requires no privileges (PR:N) and no user interaction (UI:N), with scope change into downstream tenants.
Exploitation requirements: Network reachability to the Partner Center API surface and the ability to present attacker-controlled certificate material. No prior authentication is required per the published vector.
CVE-2026-94510 — Microsoft Bookings: Authorization Bypass via User-Controlled Key (CVSS 9.9)
This is the classic insecure direct object reference / broken object-level authorization pattern (CWE-639 family): the Bookings service derives the target object (a booking, calendar, or mailbox-backed resource) from a user-controlled key in the request — an identifier the attacker can simply change — and fails to verify that the caller is authorized for that object. The result is horizontal and potentially vertical authorization bypass: reading or manipulating other organizations' booking data, staff calendars, and customer PII, and potentially modifying booking configuration.
The near-maximal score reflects the trivial exploitability: no race conditions, no memory corruption — just enumerate or guess keys and transact against objects you do not own.
CVE-2026-88131 — Microsoft Dataverse: Deserialization of Untrusted Data (CVSS 9.8)
CWE-502 (Deserialization of Untrusted Data) in Dataverse — the data backbone of Power Platform and Dynamics 365 — means an attacker can supply a crafted serialized payload that the service instantiates into objects, achieving remote code execution in the service context. Historically, deserialization flaws in business-application platforms are the quiet killers: they sit behind authenticated-looking API surfaces, execute in highly privileged service contexts, and produce minimal endpoint telemetry because the execution happens server-side.
Primary observable surface for defenders: anomalous Dataverse Web API activity — unexpected plugin/workflow registrations, unusual solution imports, bulk data operations from unfamiliar IPs or user agents, and newly created or modified SDK message processing steps.
Exploitation Status
At the time of writing, NVD has published the CVE records within the last 3 days. There is no confirmed public PoC and no confirmed CISA KEV inclusion yet — but treat that as a latency problem, not reassurance. CVSS 10.0 network-exploitable flaws in Microsoft cloud services historically attract rapid reverse engineering from patch diffs and service telemetry. Assume a 72-hour-to-2-week window before working exploits circulate, and check the CVE-2026-96207 NVD entry and CISA KEV daily.
Detection & Response
This is a technical threat — cloud-service vulnerabilities whose exploitation evidence lives in Microsoft 365 Unified Audit Log, Entra ID sign-in and audit logs, and Dataverse/Power Platform activity telemetry. The detections below focus on the post-exploitation behaviors each CVE enables, because that is where your telemetry actually has fidelity.
Sigma Rules
---
title: Anomalous Service Principal Privilege Grant Following Partner Center Access
id: 3f8c2a14-9b7e-4d51-a6c2-8e1f5d9b0a33
status: experimental
description: Detects new app role assignments, consent grants, or service principal credential additions in Entra ID audit logs — a hallmark post-exploitation behavior of a Partner Center privilege-escalation compromise (CVE-2026-96207), where an attacker mints persistent access after elevating privileges.
references:
- https://nvd.nist.gov/vuln/detail/CVE-2026-96207
- https://attack.mitre.org/techniques/T1098/
author: Security Arsenal
date: 2026/04/06
tags:
- attack.persistence
- attack.privilege_escalation
- attack.t1098
logsource:
product: azure
service: auditlogs
detection:
selection:
operationName:
- 'Add service principal credentials'
- 'Consent to application'
- 'Add app role assignment to service principal'
- 'Add delegated permission grant'
- 'Add owner to service principal'
filter_known:
initiatedBy|contains: '@securityarsenal.example.com'
condition: selection and not filter_known
falsepositives:
- Legitimate application onboarding and GDAP relationship updates by partner administrators
- Automated CI/CD pipelines that register credentials
level: high
---
title: Suspicious Microsoft Bookings Cross-Tenant Object Access
id: 7b1d4e92-3c8a-4f65-b2d9-5a6e8c1f7d44
status: experimental
description: Detects Bookings-related mailbox and calendar access events in the Unified Audit Log originating from unfamiliar IP addresses or external user agents, consistent with exploitation of CVE-2026-94510 (authorization bypass via user-controlled key) where attackers enumerate or transact against booking objects they do not own.
references:
- https://attack.mitre.org/techniques/T1530/
author: Security Arsenal
date: 2026/04/06
tags:
- attack.collection
- attack.t1530
logsource:
product: m365
service: exchange
detection:
selection:
Workload: 'Exchange'
Operation:
- 'MailboxLogin'
- 'CalendarBind'
- 'FolderBind'
- 'Send'
ObjectId|contains: 'booking'
filter_internal:
ClientIP|startswith:
- '10.'
- '192.168.'
condition: selection and not filter_internal
falsepositives:
- External customers legitimately interacting with published booking pages
- Third-party scheduling integrations
level: medium
---
title: Dataverse Plugin or Solution Modification from Unusual Source
id: c5e9a7b1-2d4f-4a83-9e6c-1b3d7f8a2e55
status: experimental
description: Detects creation or modification of Dataverse plugins, SDK message processing steps, custom workflows, or solution imports — post-exploitation persistence and execution mechanisms consistent with CVE-2026-88131 deserialization RCE in Microsoft Dataverse.
references:
- https://attack.mitre.org/techniques/T1190/
author: Security Arsenal
date: 2026/04/06
tags:
- attack.execution
- attack.persistence
- attack.t1190
logsource:
product: m365
service: powerplatform
detection:
selection_operation:
Operation|contains:
- 'PluginTypeCreate'
- 'PluginTypeUpdate'
- 'SdkMessageProcessingStepCreate'
- 'WorkflowCreate'
- 'WorkflowUpdate'
- 'SolutionImport'
- 'SolutionExport'
condition: selection_operation
falsepositives:
- Legitimate Power Platform development and ALM deployment pipelines
- ISV solution updates
level: high
KQL — Microsoft Sentinel / Defender Hunting
These queries assume you are ingesting Entra ID AuditLogs/SigninLogs, the OfficeActivity (Unified Audit Log) table, and Power Platform / Dataverse audit telemetry (via the PowerPlatformAdminActivity/Dataverse audit export or the OfficeActivity PowerPlatform workload) into Sentinel.
// HUNT 1: Partner Center post-exploitation — new credentials/consent on partner-linked service principals (CVE-2026-96207)
// Look for privilege-minting operations in the last 14 days, especially from IPs or actors
// with no prior history of performing them.
let lookback = 14d;
let baseline = AuditLogs
| where TimeGenerated between (ago(90d) .. ago(lookback))
| where OperationName has_any ("Add service principal credentials", "Consent to application", "Add app role assignment to service principal", "Add delegated permission grant", "Add owner to service principal")
| summarize by tostring(InitiatedBy.user.userPrincipalName), tostring(InitiatedBy.user.ipAddress);
AuditLogs
| where TimeGenerated > ago(lookback)
| where OperationName has_any ("Add service principal credentials", "Consent to application", "Add app role assignment to service principal", "Add delegated permission grant", "Add owner to service principal", "Add application")
| extend Actor = tostring(InitiatedBy.user.userPrincipalName), ActorIp = tostring(InitiatedBy.user.ipAddress)
| extend TargetResource = tostring(TargetResources[0].displayName)
| where not (baseline | where userPrincipalName == Actor and ipAddress == ActorIp | take 1 | isnotempty) // novel actor+IP pair
| project TimeGenerated, OperationName, Actor, ActorIp, TargetResource, Result, CorrelationId
| order by TimeGenerated desc;
// HUNT 2: Bookings authorization-bypass probing — high-volume calendar/mailbox access on Booking mailboxes (CVE-2026-94510)
// Attackers enumerating user-controlled keys generate abnormally broad object access from single sources.
OfficeActivity
| where TimeGenerated > ago(7d)
| where OfficeWorkload == "Exchange"
| where Operation in ("MailboxLogin", "CalendarBind", "FolderBind", "MessageBind")
| where OfficeObjectId has "booking" or MailboxOwnerUPN has "booking"
| summarize AccessedObjects = dcount(OfficeObjectId), Ops = count(), Operations = make_set(Operation) by ClientIP, UserId, bin(TimeGenerated, 1h)
| where AccessedObjects > 15 // tune: legitimate booking pages aggregate through service IPs; flag breadth anomalies
| order by AccessedObjects desc;
// HUNT 3: Dataverse persistence — plugin/solution/workflow changes outside deployment windows (CVE-2026-88131)
OfficeActivity
| where TimeGenerated > ago(14d)
| where OfficeWorkload =~ "PowerPlatform" or RecordType in ("PowerPlatformAdminActivity", "Dataverse")
| where Operation has_any ("Plugin", "SdkMessageProcessingStep", "SolutionImport", "Workflow")
| extend HourOfDay = datetime_part("hour", TimeGenerated)
| project TimeGenerated, Operation, UserId, ClientIP, OfficeObjectId, ResultStatus, HourOfDay
| order by TimeGenerated desc;
// HUNT 4: First-time-seen geographies/ASNs touching Partner Center sign-ins (supports CVE-2026-96207 triage)
let known_asns = SigninLogs
| where TimeGenerated between (ago(60d) .. ago(7d))
| where AppDisplayName has_any ("Partner Center", "PartnerCenter", "Microsoft Partner")
| summarize by NetworkLocationDetails, IPAddress;
SigninLogs
| where TimeGenerated > ago(7d)
| where AppDisplayName has_any ("Partner Center", "PartnerCenter", "Microsoft Partner")
| extend ASN = tostring(parse_json(NetworkLocationDetails).networkNames)
| where not (known_asns | where IPAddress == SigninLogs.IPAddress | take 1 | isnotempty)
| project TimeGenerated, UserPrincipalName, AppDisplayName, IPAddress, LocationDetails, ResultType, ConditionalAccessStatus
| order by TimeGenerated desc;
Velociraptor VQL — Endpoint Hunt
Server-side CVEs still leave client-side fingerprints: partner administrators and developers interact with these services via PowerShell modules, browsers, and API tooling from endpoints. After a deserialization RCE or partner-plane compromise, expect attacker tooling (token theft, proxying, or post-exploitation against downstream tenants) to execute from partner-operator workstations.
-- Hunt for suspicious processes interacting with Microsoft cloud service endpoints,
-- and for non-standard tooling spawning shells on partner admin workstations
LET endpoints = '(partnercenter\.microsoft\.com|api\.partnercenter\.microsoft\.com|graph\.microsoft\.com|dynamics\.com|dynamics\.com/api|api\.businesscentral)'
SELECT Pid, Ppid, Name, Exe, CommandLine, Username, CreateTime
FROM pslist()
WHERE (
-- Scripting engines or download cradles referencing partner/dataverse endpoints
(CommandLine =~ endpoints AND Name =~ '(powershell|pwsh|wscript|cscript|mshta|rundll32|curl|wget)')
OR
-- Shells spawned from office/browser processes (post-exploit staging on operator machines)
(Name =~ '(cmd|powershell|pwsh)' AND Ppid IN (
SELECT Pid FROM pslist() WHERE Name =~ '(msedge|chrome|firefox|iexplore|OUTLOOK|WINWORD|EXCEL)'))
)
ORDER BY CreateTime DESC
-- Sweep for recently modified PowerShell module caches / auth token artifacts
-- commonly abused after cloud privilege escalation (MSAL token caches, az/cli contexts)
SELECT FullPath, Size, Mtime, Atime
FROM glob(globs=[
'C:/Users/*/.IdentityService/*.bin',
'C:/Users/*/AppData/Local/.IdentityService/*',
'C:/Users/*/.Azure/*',
'C:/Users/*/.PartnerCenter*/**',
'C:/Users/*/AppData/Local/Microsoft/Office/16.0/Licensing/*'
])
WHERE Mtime > now() - 1209600 -- modified in last 14 days
ORDER BY Mtime DESC
Remediation & Verification Script
Since Microsoft patches these services server-side, the defensive script's job is verification and hardening: confirm audit logging is actually capturing the telemetry your detections depend on, inventory risky service-principal grants and GDAP relationships, and flag indicators of pre-patch exploitation.
# Security Arsenal — CVE-2026-96207 / CVE-2026-94510 / CVE-2026-88131 Triage & Hardening
# Run as a Global Reader / Security Admin. Requires: ExchangeOnlineManagement, Microsoft.Graph
Import-Module ExchangeOnlineManagement, Microsoft.Graph.Authentication, Microsoft.Graph.Identity.DirectoryManagement -ErrorAction Stop
Connect-ExchangeOnline -ShowBanner:$false
Connect-MgGraph -Scopes "AuditLog.Read.All","Directory.Read.All","Application.Read.All" -NoWelcome
# --- 1. Verify Unified Audit Log is enabled (detections depend on it) ---
$auditConfig = Get-AdminAuditLogConfig
Write-Host "[+] UnifiedAuditLogIngestionEnabled: $($auditConfig.UnifiedAuditLogIngestionEnabled)"
if (-not $auditConfig.UnifiedAuditLogIngestionEnabled) {
Set-AdminAuditLogConfig -UnifiedAuditLogIngestionEnabled $true
Write-Warning "Unified Audit Log was DISABLED — re-enabled. You had zero visibility during the exposure window."
}
# --- 2. Hunt: privileged grants & credentials added to service principals in last 14 days ---
$since = (Get-Date).AddDays(-14).ToString("yyyy-MM-dd")
$grants = Get-MgAuditLogDirectoryAudit -Filter "activityDateTime ge $since" -All |
Where-Object { $_.ActivityDisplayName -match 'Add service principal credentials|Consent to application|Add app role assignment|Add delegated permission grant|Add owner to service principal' }
$grants | Select-Object ActivityDateTime, ActivityDisplayName,
@{n='Actor';e={$_.InitiatedBy.User.UserPrincipalName}},
@{n='ActorIp';e={$_.InitiatedBy.User.IpAddress}},
@{n='Target';e={$_.TargetResources[0].DisplayName}}, Result |
Export-Csv -Path ".\SvcPrincipal_Grants_$($since).csv" -NoTypeInformation
Write-Host "[+] $($grants.Count) privilege-minting events found — review .\SvcPrincipal_Grants_$($since).csv for anything you cannot attribute to change control."
# --- 3. Inventory high-privilege app role assignments (Partner Center blast radius) ---
$dangerousRoles = @('Directory.ReadWrite.All','RoleManagement.ReadWrite.Directory','Application.ReadWrite.All','AppRoleAssignment.ReadWrite.All','Mail.ReadWrite','full_access_as_app')
$sps = Get-MgServicePrincipal -All -Property "AppRoleAssignments,DisplayName,Id"
$risky = foreach ($sp in $sps) {
foreach ($ara in $sp.AppRoleAssignments) {
$risky += [pscustomobject]@{ ServicePrincipal=$sp.DisplayName; SPId=$sp.Id; ResourceId=$ara.ResourceId; AppRoleId=$ara.AppRoleId; Created=$ara.CreatedDateTime }
}
}
$risky | Export-Csv -Path ".\AppRole_Inventory.csv" -NoTypeInformation
Write-Host "[+] Exported $($risky.Count) app role assignments. Cross-reference AppRoleIds against MSGraph dangerous-role GUIDs and validate every grant against business need."
# --- 4. Enforce: require admin approval for user consent (limits consent-phish follow-on) ---
$consentPolicy = Get-MgPolicyAuthorizationPolicy
if ($consentPolicy.DefaultUserRolePermissions.PermissionGrantPoliciesAssigned -notcontains 'ManagePermissionGrantsForSelf.microsoft-user-default-low') {
Write-Warning "User consent is not restricted to low-risk permissions. Recommend blocking user consent entirely or enabling the admin consent workflow: Entra ID > Enterprise applications > Consent and permissions."
}
# --- 5. Bookings hygiene: enumerate Bookings-enabled mailboxes for access review ---
$bookingsMailboxes = Get-Mailbox -RecipientTypeDetails SchedulingMailbox -ResultSize Unlimited
Write-Host "[+] $($bookingsMailboxes.Count) Bookings/scheduling mailboxes found. Review their calendar access (Get-MailboxFolderPermission) for external or anonymous sharing."
$bookingsMailboxes | ForEach-Object {
Get-MailboxFolderPermission -Identity "$($_.Alias):\Calendar" -ErrorAction SilentlyContinue |
Where-Object { $_.User.DisplayName -match 'Anonymous|Default' -and $_.AccessRights -notmatch 'None|AvailabilityOnly' }
} | Export-Csv -Path ".\Bookings_Calendar_Exposure.csv" -NoTypeInformation
Write-Host "[+] Calendar exposure review exported to .\Bookings_Calendar_Exposure.csv"
Disconnect-ExchangeOnline -Confirm:$false -ErrorAction SilentlyContinue
Remediation
1. Confirm Microsoft's server-side remediation status. All three CVEs affect Microsoft-operated services, so patches deploy on Microsoft's side. Do not assume closure — open the MSRC Security Update Guide and the NVD entry for CVE-2026-96207, and confirm each CVE's status shows "Exploitation: No" / fixed with a remediation date that precedes your hunting window. Subscribe to MSRC CVRF/RSS feeds for these CVE IDs.
2. Hunt for pre-patch exploitation — this is non-negotiable. The exposure window existed before Microsoft deployed fixes. Execute the KQL hunts above over at least a 90-day lookback (audit retention permitting). Priority artifacts:
- Any service principal credential additions or consent grants you cannot tie to a change ticket (CVE-2026-96207 follow-on).
- Breadth anomalies in Bookings mailbox/calendar access from single IPs (CVE-2026-94510).
- Plugin registrations, SDK message steps, or solution imports in Dataverse/Power Platform outside deployment windows (CVE-2026-88131).
3. Reduce the Partner Center blast radius immediately.
- Audit all GDAP relationships (Partner Center > Customers > Admin relationships). Remove any relationship your technicians are not actively using; ensure GDAP roles are least-privilege and time-bound.
- Enforce MFA + Conditional Access on every partner user account — Partner Center mandates MFA, but verify no legacy exceptions exist. Block legacy authentication tenant-wide.
- Rotate credentials on partner-linked service principals created before the patch date if you see any anomalous audit activity.
4. Harden against the authorization-bypass pattern (Bookings). Review calendar folder permissions on scheduling mailboxes (script step 5), disable Bookings for business units that do not need it (Set-OrganizationConfig / Bookings toggle in M365 admin center), and treat booking data as PII in your DLP policies.
5. Constrain Dataverse/Power Platform extensibility. Restrict who can register plugins and import solutions: enforce Power Platform DLP policies, disable trial/developer environments with default-open access, and route all ALM through managed pipelines so an out-of-band plugin registration is, by definition, an incident.
6. Watch CISA KEV daily. Given a CVSS 10.0 network-exploitable Microsoft cloud flaw, KEV inclusion is plausible. If any of these CVEs lands in KEV, federal agencies face BOD 22-01 deadlines (typically 2-3 weeks), and you should treat your own remediation/validation timeline the same way.
7. If you find evidence of exploitation: revoke affected service principal credentials and refresh tokens (Revoke-MgUserSignInSession / remove credentials via Graph), invalidate refresh tokens tenant-wide for affected accounts, preserve Unified Audit Log and Entra audit exports before retention rolls over, and engage IR — a Partner Center elevation is a multi-tenant event and may carry notification obligations to downstream customers.
Related Resources
Security Arsenal Penetration Testing Services AlertMonitor Platform Book a SOC Assessment vulnerability-management Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.