Cross-Site Scripting Vulnerability in Azure Portal by Microsoft
CVE-2026-83946

8.2HIGH

Key Information:

Vendor

Microsoft

Vendor
CVE Published:
17 September 2026

What is CVE-2026-83946?

A cross-site scripting (XSS) vulnerability in Azure Portal permits unauthorized attackers to inject malicious scripts into web pages, potentially altering the way content is presented to users. This imperfection allows for the manipulation of user sessions and can lead to spoofing attacks, compromising user authentication and data integrity across the network.

Affected Version(s)

Azure Portal -

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.