The vendor has published a fix. Version details are below where the sources state them.
Steps
Written by AI from the record
Check whether your organization uses Microsoft Purview eDiscovery (not just general Purview) and confirm the currently installed/allowed configuration and update level in your environment.
Open the Microsoft MSRC update guidance for CVE-2026-65668 and confirm you are on the fully remediated version/build listed there.
Apply the Microsoft Purview eDiscovery remediation from the MSRC update guide as soon as possible (start with non-production systems first if you need validation).
If you cannot patch immediately, reduce who can authenticate to Purview eDiscovery (tighten access to only required staff/roles) and monitor for abnormal privilege or admin actions related to eDiscovery.
Improper access control in Microsoft Purview eDiscovery allows an authorized attacker to elevate privileges over a network.
In plain language
Written by AI from the record
Microsoft Purview eDiscovery has a permissions flaw where a low-privilege, authenticated attacker could gain higher privileges over the network, so most small businesses using Purview eDiscovery should act to install Microsoft’s fix promptly.
CVE-2026-65668 is an Elevation of Privilege issue in Microsoft Purview eDiscovery caused by improper access controls (CWE-284), where an authorized/low-privileged attacker can trigger a privilege increase over the network without user interaction.
If you're affected
Account and permissions takeover
Potential access to sensitive documents
System or service disruption
Higher risk of follow-on attacks
What is it
Think of Microsoft Purview eDiscovery as a “library back office” where authorized staff find and manage sensitive case materials. This bug is like someone being able to sneak past a door guard with only a low-level badge and then briefly getting access to higher-level areas. If an attacker already has some approved access, they may be able to expand what they can do—potentially increasing exposure and disrupting operations.
Who is affected
This matters if your business uses Microsoft Purview eDiscovery and you have users, integrations, or service access that can authenticate to it with low privileges. The vulnerability requires an attacker to be authenticated/authorized, so it’s not a simple “anyone on the internet” flaw. The risk is mainly present when an attacker can reach Purview eDiscovery through normal network access and has some level of authenticated access.
How urgent is it
This is urgent because it’s an elevation of privilege problem in a sensitive eDiscovery workflow, and it has a high severity rating. Security reporting and sustained attention link this issue to the Lazarus group, which raises the likelihood that motivated attackers may target it. Act now to install Microsoft’s remediation rather than waiting.
What to do — in detail
Confirm usage and scope
Verify that Microsoft Purview eDiscovery is actively used in your tenant (as opposed to only general Purview features).
Identify which identities (staff roles, service accounts, automation, third-party integrations) have access to eDiscovery-related functions.
Check for exposure
Use the Microsoft MSRC update guide for CVE-2026-65668 to determine whether your current deployed/available Microsoft Purview eDiscovery configuration is covered by the vulnerable state and what “fully remediated” version/build means for your environment.
If you manage this via standard Microsoft update/service lifecycle, the practical check is whether you are running the state Microsoft indicates is fixed in the MSRC guidance.
Note: This CVE is not listed in the CISA KEV catalog based on the provided findings, so prioritize by the vendor fix guidance and your internal risk assessment—but given the RED verdict, treat it as high priority regardless.
Technical context
CVE-2026-65668 is a Microsoft Purview eDiscovery Elevation of Privilege vulnerability (CWE-284) with network attack capability. The core mechanism is improper access control that allows an authorized/low-privileged attacker to gain higher privileges over the network, with no user interaction required. Publicly, there is no clear dated press report of exploitation and no public exploit code is on record in the provided findings; however, sustained attention and actor association (Lazarus group) increase threat relevance.
The traffic-light verdict is RED. KEV status: not listed in CISA KEV (per findings). EPSS: 0.4% (predicted likelihood) with a flat trend; this is not the basis for urgency here due to the confirmed-risk posture implied by the RED verdict and the reported sustained attention.
This is a general assessment based on public vulnerability data. It does not account for your specific infrastructure — when in doubt, consult a security specialist.