CVE-2026-42826

Exposure of sensitive information to an unauthorized actor in Azure DevOps allows an unauthorized attacker to disclose information over a network.

critical 10.0 CVSS 3.1
Published: May 7, 2026
Modified: May 8, 2026
Vendor: Microsoft
Product: Azure Devops