PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-73851 microsoft CVE debrief

CVE-2026-73851 debrief based on the supplied source corpus. The CVE record was published on 2026-08-17T15:16:57.980Z and has not been modified since then. This vulnerability in Kiota, an OpenAPI-based HTTP Client code generator, allows for potential file inclusion or disclosure outside the intended package boundary. An attacker controlling or tampering with the OpenAPI description can supply a file reference resolving outside the manifest package. Defenders should verify configurations, restrict OpenAPI descriptions, and update to fixed versions 1.29.1 or 1.34.0.

Vendor
microsoft
Product
kiota
CVSS
MEDIUM 6.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-17
Original CVE updated
2026-09-18
Advisory published
2026-08-17
Advisory updated
2026-09-18

Who should care

Defenders responsible for Kiota deployments, AI hosts, and systems consuming generated manifests should assess exposure and prioritize updates to fixed versions. This includes verifying configurations, restricting OpenAPI descriptions, and monitoring for suspicious activity related to Kiota deployments. Security teams and vulnerability management teams should also review and act on this vulnerability.

Why it matters

CVE-2026-73851 allows potential file inclusion or disclosure in Kiota deployments. Defenders should verify configurations, restrict OpenAPI descriptions, and update to fixed versions.

  • Potential inclusion or disclosure of files outside the intended package boundary
  • Verification of Kiota configurations and OpenAPI descriptions is necessary
  • Updating to fixed versions 1.29.1 or 1.34.0 is required
  • Monitoring for suspicious activity related to Kiota deployments is recommended

Technical summary

Kiota, an OpenAPI-based HTTP Client code generator, is vulnerable to file inclusion or disclosure outside the intended package boundary. An attacker controlling or tampering with the OpenAPI description can supply a file reference resolving outside the manifest package. This can lead to inclusion or disclosure of files outside the intended package boundary when the generated manifest is deployed and consumed by an AI host. The vulnerability is fixed in versions 1.29.1 and 1.34.0. Defenders should prioritize verifying Kiota configurations and updating to fixed versions.

Defensive priority

Defenders should prioritize verifying Kiota configurations and updating to fixed versions 1.29.1 or 1.34.0.

Recommended defensive actions

  • Verify Kiota configurations and update to fixed versions 1.29.1 or 1.34.0
  • Review and restrict OpenAPI descriptions consumed by Kiota
  • Monitor for suspicious activity related to Kiota deployments
  • Perform vulnerability scanning and asset inventory of Kiota deployments
  • Implement compensating controls for exposed systems while remediation is scheduled and verified
  • Track exceptions and retest remediated assets
  • Review relevant monitoring, detection, and logs for exposed assets

Evidence notes

The CVE record and source references indicate a vulnerability in Kiota, allowing for potential file inclusion or disclosure outside the intended package boundary. Evidence is limited to CVE and NVD details. Defenders should verify Kiota configurations, review OpenAPI descriptions, and monitor for suspicious activity related to Kiota deployments.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-73851 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-73851

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-73851 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-73851

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.