Authorization Bypass in Microsoft Azure Active Directory B2C
CVE-2026-83711

10CRITICAL

Key Information:

Vendor

Microsoft

Status
Vendor
CVE Published:
3 September 2026

What is CVE-2026-83711?

An authorization bypass vulnerability exists in Microsoft Azure Active Directory B2C, where an attacker can manipulate user-controlled keys to gain elevated privileges. This vulnerability allows unauthorized users to perform actions that should only be permitted to authorized users, potentially compromising sensitive data and security within the network. Prompt patching is required to mitigate the risk associated with this vulnerability.

Affected Version(s)

Entra -

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.