PatchSiren cyber security CVE debrief
CVE-2026-73851 microsoft CVE debrief
CVE-2026-73851 debrief based on the supplied source corpus. The CVE record was published on 2026-08-17T15:16:57.980Z and has not been modified since then. This vulnerability in Kiota, an OpenAPI-based HTTP Client code generator, allows for potential file inclusion or disclosure outside the intended package boundary. An attacker controlling or tampering with the OpenAPI description can supply a file reference resolving outside the manifest package. Defenders should verify configurations, restrict OpenAPI descriptions, and update to fixed versions 1.29.1 or 1.34.0.
- Vendor
- microsoft
- Product
- kiota
- CVSS
- MEDIUM 6.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-17
- Original CVE updated
- 2026-09-18
- Advisory published
- 2026-08-17
- Advisory updated
- 2026-09-18
Who should care
Defenders responsible for Kiota deployments, AI hosts, and systems consuming generated manifests should assess exposure and prioritize updates to fixed versions. This includes verifying configurations, restricting OpenAPI descriptions, and monitoring for suspicious activity related to Kiota deployments. Security teams and vulnerability management teams should also review and act on this vulnerability.
Why it matters
CVE-2026-73851 allows potential file inclusion or disclosure in Kiota deployments. Defenders should verify configurations, restrict OpenAPI descriptions, and update to fixed versions.
- Potential inclusion or disclosure of files outside the intended package boundary
- Verification of Kiota configurations and OpenAPI descriptions is necessary
- Updating to fixed versions 1.29.1 or 1.34.0 is required
- Monitoring for suspicious activity related to Kiota deployments is recommended
Technical summary
Kiota, an OpenAPI-based HTTP Client code generator, is vulnerable to file inclusion or disclosure outside the intended package boundary. An attacker controlling or tampering with the OpenAPI description can supply a file reference resolving outside the manifest package. This can lead to inclusion or disclosure of files outside the intended package boundary when the generated manifest is deployed and consumed by an AI host. The vulnerability is fixed in versions 1.29.1 and 1.34.0. Defenders should prioritize verifying Kiota configurations and updating to fixed versions.
Defensive priority
Defenders should prioritize verifying Kiota configurations and updating to fixed versions 1.29.1 or 1.34.0.
Recommended defensive actions
- Verify Kiota configurations and update to fixed versions 1.29.1 or 1.34.0
- Review and restrict OpenAPI descriptions consumed by Kiota
- Monitor for suspicious activity related to Kiota deployments
- Perform vulnerability scanning and asset inventory of Kiota deployments
- Implement compensating controls for exposed systems while remediation is scheduled and verified
- Track exceptions and retest remediated assets
- Review relevant monitoring, detection, and logs for exposed assets
Evidence notes
The CVE record and source references indicate a vulnerability in Kiota, allowing for potential file inclusion or disclosure outside the intended package boundary. Evidence is limited to CVE and NVD details. Defenders should verify Kiota configurations, review OpenAPI descriptions, and monitor for suspicious activity related to Kiota deployments.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-73851 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-73851
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-73851 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-73851
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/microsoft/kiota/commit/430008e9d700b3fe80f206c672415cfbd8e830e7
-
Source reference
Unverified legacy reference
URL: https://github.com/microsoft/kiota/commit/de3d18d9fe31ced4ac749728d3a2f94811f59268
-
Source reference
Unverified legacy reference
URL: https://github.com/microsoft/kiota/issues/7912
-
Source reference
Unverified legacy reference
URL: https://github.com/microsoft/kiota/pull/7910
-
Source reference
Unverified legacy reference
URL: https://github.com/microsoft/kiota/pull/7913
-
Source reference
Unverified legacy reference
URL: https://github.com/microsoft/kiota/releases/tag/v1.29.1
-
Source reference
Unverified legacy reference
URL: https://github.com/microsoft/kiota/releases/tag/v1.34.0
-
Source reference
Unverified legacy reference
URL: https://github.com/microsoft/kiota/security/advisories/GHSA-p5rm-jg5c-8c77
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.