Vulnerability  ·  2026-10-07

Microsoft SimpleChat MCP stdio authorization ordering flaw — low-priv user reaches OS process execution as service identity

VulnerabilityHigh impactGlobalCVE-2026-105797
An authorization-ordering flaw in POST /api/user/plugins lets an authenticated low-privileged user omit the top-level MCP type so the stdio inspection check is skipped; the stored personal action then reaches the MCP stdio plugin factory and starts an attacker-selected operating-system process under the application service identity when the tool is invoked. CISA SSVC lists exploitation=poc. Requires personal plugins enabled and governance permitting MCP actions.
SimpleChat is Microsoft's secure document-grounded AI conversation/workspace app. The MCP stdio tool surface is the agent-command-execution boundary; bypassing its governance gate to start arbitrary OS processes under the service account can expose or modify secrets and data available to the service and disrupt the app — a low-privileged-to-service-account escalation on the AI platform.
Authenticated low-priv API call to POST /api/user/plugins omitting the MCP type to bypass the admin stdio check, then invoking the stored action to execute a chosen binary under the service identity.
Microsoft SimpleChat 0.261.003 and 0.261.027; fixed 0.261.031
Upgrade to SimpleChat 0.261.031; restrict personal-plugins/MCP-Actions governance settings in the interim.
NVD CVE-2026-105797GitHub advisory GHSA-h4mw-qw8m-5x4jNVD CVE-2026-105798
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →