Description
Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.
Published: 2026-09-03
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

This vulnerability exists in Microsoft Azure Active Directory B2C where an authorization bypass allows an attacker to tamper with a user-controlled key to elevate privileges. The flaw is rooted in improper validation of the key, enabling a non‑privileged user to gain higher rights and potentially control the tenant or access sensitive data. Because the attacker only needs a crafted key, the impact is a direct privilege elevation that compromises confidentiality, integrity, and availability of the tenant’s services.

Affected Systems

Microsoft Entra Azure Active Directory B2C is affected. No specific product versions were disclosed, so any deployment of Azure AD B2C that has not applied the latest security updates may be vulnerable.

Risk and Exploitability

The CVSS score of 10 highlights a critical severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. While an explicit attack vector is not stated, the likely vector is a remote exploitation of the B2C API using a user‑supplied key, as inferred from the description. No additional prerequisites are mentioned, suggesting that an attacker can exploit the flaw with minimal information beyond the ability to create or modify a key. Given the lack of EPSS data, evaluation relies on CVSS and potential for exploitation, indicating a high risk to affected tenants.

Generated by OpenCVE AI on September 4, 2026 at 00:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Follow Microsoft’s guidance on the update guide at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83711 and apply any released security update that addresses the authorization bypass.
  • If a patch is not yet available, enforce strict least‑privilege access on user‑controlled keys and consider disabling or restricting new key creation until remediation is possible.
  • Continuously monitor Azure AD B2C logs for anomalous privilege‑escalation activity and investigate any suspicious key usage.

Generated by OpenCVE AI on September 4, 2026 at 00:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 05 Sep 2026 05:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 04 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft entra Id
Vendors & Products Microsoft entra Id

Thu, 03 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
Description Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.
Title Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft azure Active Directory B2c
Weaknesses CWE-639
CPEs cpe:2.3:a:microsoft:azure_active_directory_b2c:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft azure Active Directory B2c
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Azure Active Directory B2c Entra Id
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-23T22:40:36.638Z

Reserved: 2026-08-31T22:43:34.220Z

Link: CVE-2026-83711

cve-icon Vulnrichment

Updated: 2026-09-04T19:50:49.383Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-03T23:17:20.500

Modified: 2026-09-08T15:32:16.500

Link: CVE-2026-83711

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T15:15:14Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key