Improper Privilege Management in Azure Entra ID Affects Microsoft Products
CVE-2026-23663
7.5HIGH
Key Information:
- Vendor
Microsoft
- Vendor
- CVE Published:
- 22 May 2026
What is CVE-2026-23663?
This vulnerability allows unauthorized attackers to elevate privileges within the Azure Entra ID environment. By exploiting insufficient privilege management controls, an attacker can gain unauthorized access to sensitive data or system resources over the network. It is critical for organizations using Azure Entra ID to promptly review their security measures and apply necessary updates to mitigate this vulnerability.
Affected Version(s)
Microsoft Global Secure Access (GSA) -