CVE-2026-58201

Lokka is a Model Context Protocol server for Microsoft 365, including Microsoft Graph and other services. Prior to 2.1.2, the Lokka-Microsoft tool in src/mcp/src/main.ts uses direct URL string concatenation to append the user-controlled path value to the management.azure.com base URL. A specially crafted path can alter URL authority parsing and cause an Azure Resource Manager bearer token to be sent to an unintended host. This issue is fixed in version 2.1.2.

  • Published Sep 15, 2026
  • CVSS 8.7 high
  • 0.5% chance of exploitation in the next 30 days (EPSS)
  • A fix is available

Affected software

CVE-2026-58201 at the National Vulnerability Database