Disclosure summary
CVE-2026-26030 is a Remote Code Execution vulnerability that has been identified in Microsoft Semantic Kernel Python SDK, specifically within the InMemoryVectorStore filter functionality. GitHub created this CVE on their behalf. GitHub created this CVE on their behalf. This document incorporates updates in the Microsoft Semantic Kernel Repository which address this vulnerability. Please see CVE-2026-26030 for more information.
Source-reported weakness categories
CWE-749
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
Microsoft Security Updates (CVRF) · 2026-Mar
Open original source · Updated Mar 12, 2026
GitHub: CVE-2026-26030 Microsoft Semantic Kernel InMemoryVectorStore filter functionality vulnerable
Maximum of vendor-reported product scores; products and fixed builds are associations, not a universal affected-version statement.
Microsoft maximum product score: 9.9
| Vendor | Product / association | Version / bounds |
|---|---|---|
| Microsoft update guide | Microsoft Semantic Kernel Python SDK | (MSRC status code 3) |
Vendor remediation references
- Release Notes · build 1.39.4 · product IDs 21023
- Vendor guidance · product IDs 21023
- Release Notes · build 1.39.4 · product IDs 21023
- Vendor guidance · product IDs 21023
- The following has been identified as a workaround for this vulnerability. Avoid using InMemoryVectorStore for production scenarios.
Original records & references
- NIST NVD record
- CVE Program record
- msrc.microsoft.com — Vendor advisory
PUBLISHED 2026-03-10T03:00:00-04:00
MODIFIED 2026-03-12T03:00:00-04:00
INGESTED 2026-10-08T12:45:10-04:00