Application Insights Profiler Elevation of Privilege Vulnerability

Date Aug 6, 2026
Type Patch Tuesday
Signal High-risk advisory
Vendor / Product Microsoft ยท Application Insights Profiler
CVE CVE-2026-49163
High-risk advisory CVE-2026-49163

Summary

Improper limitation of a pathname to a restricted directory ('path traversal') in Application Insights Profiler allows an authorized attacker to elevate privileges over a network. Published in August 2026 Early Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No.

Why it matters

Microsoft published this item through its Security Update Guide, making it part of Patch Tuesday triage for affected Windows, cloud, or application estates. EPSS percentile: 46%.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-49163. Confirm whether Application Insights Profiler is deployed, then apply the current security update or documented mitigation. CVSS score: 8.8. EPSS probability: 0.6%; percentile: 46%.

Sources

PatchBrief uses public sources. It does not scan environments, verify exposure, or replace vendor guidance.