Elevation of Privilege Vulnerability in Azure IoT Central by Microsoft
CVE-2026-21515

9.9CRITICAL

Key Information:

Vendor

Microsoft

Vendor
CVE Published:
24 April 2026

What is CVE-2026-21515?

The vulnerability in Azure IoT Central permits an authorized attacker to gain elevated privileges within the network, potentially exposing sensitive information to unauthorized actors. This security flaw undermines the integrity and confidentiality of the IoT environment, emphasizing the need for immediate attention and remedial measures.

Affected Version(s)

Azure IOT Central -

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.