CVE-2026-83711: Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerability
Published Sep 3, 2026
·Updated
Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.
Other sources
Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerability
— Microsoft
Affected Software
1 affected component
Microsoft Azure Active Directory B2C
Event History
Sep 3, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·02:00 PM
Description
CVE Published
via MITRE·10:59 PM
Data Sourced
via MITRE·10:59 PM
DescriptionSeverity
Frequently Asked Questions
1
Does an attacker need an existing account or any assigned privileges?
No. The vulnerability is rated PR:N and is described as exploitable by an unauthorized attacker over the network.
2
Is user interaction required for exploitation?
No. The CVSS vector specifies UI:N, indicating exploitation does not require a victim to take an action.
3
What security impact is indicated?
The rating indicates high confidentiality and integrity impact, with a changed scope. No availability impact is indicated.