Description
Improper neutralization of input during web page generation ('cross-site scripting') in Azure Portal allows an unauthorized attacker to perform spoofing over a network.
Published: 2026-09-17
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting enabling spoofing and unauthorized content injection
Action: Patch ASAP
AI Analysis

Impact

The flaw is an improper neutralization of user input during web page generation, resulting in a cross‑site scripting (XSS) vulnerability. An attacker who can supply specially crafted input to the Azure Portal is able to inject malicious content that is rendered to other users. This enables spoofing, allowing the attacker to convince legitimate users that they are interacting with legitimate portal pages while actually seeing attacker‑controlled content. The injected content can mimic authentic portal elements, potentially leading to phishing or credential theft.

Affected Systems

Microsoft Azure Portal is the affected product. Specific version information is not disclosed, so all Azure Portal instances remain potentially impacted until a vendor‑provided patch is applied.

Risk and Exploitability

The CVSS score of 8.2 indicates high severity, yet the EPSS score of less than 1% suggests a low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog, implying it has not been actively exploited in the wild. Likely access requires the attacker to influence input that the portal processes—this could be achieved through network access to the portal's interface or by tricking a user into submitting malicious data. Because the flaw does not require privileged access, any user with the ability to interact with the portal could potentially be exploited.

Generated by OpenCVE AI on September 18, 2026 at 23:00 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Microsoft Azure Portal patch or update from the official Microsoft security update hub
  • Implement Azure Security Center or equivalent monitoring to detect anomalous page rendering or injection attempts
  • Configure a web application firewall to filter and block common XSS payloads, ensuring only trusted content is rendered

Generated by OpenCVE AI on September 18, 2026 at 23:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 25 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:microsoft:azure_portal:-:*:*:*:*:*:*:*

Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Description Improper neutralization of input during web page generation ('cross-site scripting') in Azure Portal allows an unauthorized attacker to perform spoofing over a network.
Title Azure Portal Spoofing Vulnerability
First Time appeared Microsoft
Microsoft azure Portal
Weaknesses CWE-79
CPEs cpe:2.3:a:microsoft:azure_portal:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft azure Portal
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Azure Portal
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-10-08T18:20:39.818Z

Reserved: 2026-08-31T23:40:59.641Z

Link: CVE-2026-83946

cve-icon Vulnrichment

Updated: 2026-09-18T14:30:44.960Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-18T00:17:44.960

Modified: 2026-09-25T19:51:29.090

Link: CVE-2026-83946

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T23:15:17Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')