# Microsoft Exchange SSRF Vulnerability (CVE-2026-45504) — Public PoC Exploit Enables Authenticated Arbitrary File Read

> CVE-2026-45504 is a CVSS 8.8 server-side request forgery flaw in Microsoft Exchange's OneDriveProUtilities component (TryTwice/GetWacUrl functions) that lets an authenticated, low-privileged user craft an EWS ReferenceAttachment with a malicious ProviderEndpointUrl pointing to attacker infrastructure. Exchange fails to validate the URL scheme of the WOPI-returned WebApplicationUrl, allowing a file:// URI (hidden behind a fragment '#' trick) to be used for arbitrary local file read. HawkTrace publicly released a PoC exploit on GitHub on 2026-07-03; Microsoft had already patched the flaw on 2026-06-09.

- **Published:** 2026-07-05T00:00:00Z
- **Last reviewed:** 2026-07-05T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1113
- **ID:** TL-2026-1113
- **Severity:** HIGH (CVSS 8.8)
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 18 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-45504

## Description

CVE-2026-45504 is a server-side request forgery (SSRF) vulnerability affecting on-premises Microsoft Exchange Server 2016 (CU23), Exchange Server 2019 (CU14/CU15), and Exchange Server Subscription Edition (RTM builds prior to 15.02.2562.043). The root cause lies in Exchange's OneDriveProUtilities component, specifically the TryTwice and GetWacUrl helper functions used to build WAC (Web Application Companion / Office Online) document-preview URLs when a user interacts with a reference attachment.

An authenticated, low-privileged user can use Exchange Web Services (EWS) to create a ReferenceAttachment whose ProviderEndpointUrl points to an attacker-controlled HTTP server rather than a legitimate SharePoint/OneDrive/WOPI host. When the attachment is previewed, Exchange's backend issues a GetWopiTargetPropertiesByUrl request to that attacker-controlled endpoint to retrieve WOPI metadata. The malicious server responds with a crafted WebApplicationUrl field containing a file:// URI (for example, file:///C:/Windows/win.ini#) instead of a legitimate https:// WAC URL.

Because Exchange does not validate the URL scheme of the WebApplicationUrl value returned by the WOPI provider, it accepts the file:// scheme and proceeds to construct the final request. A '#' fragment character appended after the file path causes the URI parser to treat everything that follows (including OAuth access_token query parameters Exchange normally appends) as a fragment, which is discarded rather than appended to the path. Exchange then issues a FileWebRequest against the local filesystem path and returns the file's contents through the same response channel used for legitimate WAC previews — converting what starts as an SSRF primitive into a full arbitrary local file read on the Exchange server, achievable by any authenticated low-privileged mailbox user.

Security researchers at HawkTrace discovered and reported the flaw, and Microsoft addressed it in the June 9, 2026 Patch Tuesday cycle via KB5094139 (Subscription Edition RTM), KB5094142 (Exchange 2019 CU14), KB5094140 (Exchange 2019 CU15), and KB5094144 (Exchange 2016 CU23). Microsoft's initial exploitability assessment rated the issue 'Exploitation Less Likely.' On 2026-07-03, HawkTrace published a detailed technical write-up and a public proof-of-concept exploit on GitHub that automates malicious WOPI server setup, Exchange authentication, and arbitrary file requests (demonstrated against C:\Windows\win.ini), substantially lowering the barrier to exploitation for any unpatched, internet- or intranet-reachable Exchange server. There is no confirmed evidence of in-the-wild exploitation and the CVE does not currently appear in the CISA Known Exploited Vulnerabilities catalog, but the public, weaponized PoC materially raises near-term risk for organizations that have not yet applied the June 2026 updates, particularly those running Exchange 2016/2019 out of mainstream support and relying on the Extended Security Updates (ESU) program.

Post-exploitation, arbitrary local file read on an Exchange server can expose highly sensitive material — IIS/OWA web.config files containing connection strings and machine keys, certificate private key files, configuration data, and other artifacts that can be leveraged for further privilege escalation, credential theft, or full server/domain compromise — making this a high-value primitive even though the vulnerability itself does not include a code-execution step.

## MITRE ATT&CK

- T1595.002 Vulnerability Scanning
- T1583.004 Server
- T1587.004 Exploits
- T1190 Exploit Public-Facing Application
- T1566.001 Spearphishing Attachment
- T1204.002 Malicious File
- T1068 Exploitation for Privilege Escalation
- T1211 Exploitation for Stealth
- T1027 Obfuscated Files or Information
- T1552.001 Credentials In Files
- T1082 System Information Discovery
- T1083 File and Directory Discovery
- T1210 Exploitation of Remote Services
- T1005 Data from Local System
- T1071.001 Web Protocols
- T1090 Proxy

## Sources

- [Microsoft Exchange SSRF Vulnerability Details Released Along With Public PoC Exploit](https://cybersecuritynews.com/exchange-ssrf-poc-exploit-released/)
- [CVE-2026-45504 Microsoft Exchange SSRF via File Read](https://hawktrace.com/blog/CVE-2026-45504/)
- [hawktrace/CVE-2026-45504 PoC exploit](https://github.com/hawktrace/CVE-2026-45504)
- [Microsoft Exchange SSRF Vulnerability Lets Low-Privileged Attackers Read Arbitrary Files](https://gbhackers.com/microsoft-exchange-ssrf-vulnerability/)
- [CVE-2026-45504 - Security Update Guide - Microsoft Exchange Server Elevation of Privilege Vulnerability](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45504)
- [NVD - CVE-2026-45504](https://nvd.nist.gov/vuln/detail/CVE-2026-45504)
- [PoC Released for Microsoft Exchange SSRF Flaw That Lets Low-Privileged Users Read Files](https://cyberpress.org/microsoft-exchange-ssrf-flaw/)
- [Released: June 2026 Exchange Server Security Updates](https://techcommunity.microsoft.com/blog/exchange/released-june-2026-exchange-server-security-updates/4524491)
- [Description of the security update for Microsoft Exchange Server 2019 CU14: June 09, 2026 (KB5094142)](https://support.microsoft.com/en-us/topic/description-of-the-security-update-for-microsoft-exchange-server-2019-cu14-june-09-2026-kb5094142-199c2365-df8e-4dfe-9f43-fc741c13949d)
- [Description of the security update for Microsoft Exchange Server 2016 CU23: June 09, 2026 (KB5094144)](https://support.microsoft.com/help/5094144)
- [Description of the security update for Microsoft Exchange Server 2019 CU15: June 09, 2026 (KB5094140)](https://support.microsoft.com/en-us/topic/description-of-the-security-update-for-microsoft-exchange-server-2019-cu15-june-09-2026-kb5094140-87cde12f-2657-4c21-b587-15383cab1137)
- [Description of the security update for Microsoft Exchange Server Subscription Edition RTM: June 09, 2026 (KB5094139)](https://support.microsoft.com/en-us/topic/description-of-the-security-update-for-microsoft-exchange-server-subscription-edition-rtm-june-09-2026-kb5094139-d9713301-1e65-40f9-a14a-2c7b8ae711d1)
- [June 2026 Patch Tuesday: Updates and Analysis](https://www.crowdstrike.com/en-us/blog/patch-tuesday-analysis-june-2026/)
- [Patch Tuesday - June 2026](https://www.rapid7.com/blog/post/em-patch-tuesday-june-2026/)
- [Microsoft: Microsoft Exchange SSRF Vulnerability Details Released Along With Public PoC Exploit](https://blog.rankiteo.com/mic1783067043-microsoft-vulnerability-july-2026/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1113
