CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2026-24303

CVSS 9.6v3.1pub. 2026-04-23upd. 2026-04-28

Improper access control in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network.

🤖 AI Analysis
How it works

The vulnerability consists of improper access control (CWE-284) in Microsoft Partner Center. An authenticated attacker with basic privileges can, without interaction from the victim, send a specially crafted network request that bypasses authorization mechanisms. As a result, it is possible to obtain privileges exceeding those the attacker is authorized for. The network attack vector and lack of attack complexity requirements significantly lower the threshold for conducting the attack.

Impact

An attacker can gain unauthorized access to resources and data of other users or organizations in Microsoft Partner Center, potentially compromising data confidentiality and integrity in multi-tenant environments (scope changed).

Mitigation & patch

Patches available from the vendor should be applied in accordance with the references — details at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-24303

Who is affected

Microsoft Partner Center — versions indicated in vendor references

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
  • Microsoft Partner Center

    APP
    Microsoft
    all versions
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2025-65041CRITICAL10.0PL ✓same product

Nieprawidłowa autoryzacja w Microsoft Partner Center — privilege escalation

CVE-2025-29814CRITICAL9.3PL ✓same product

Nieautoryzowana eskalacja uprawnień w Microsoft Partner Center

CVE-2024-49035HIGH8.7⚠ KEVsame product

An improper access control vulnerability in Partner.Microsoft.com allows an a unauthenticated attacker to elev...

CVE-2026-69558HIGH8.6same product

Authorization bypass through user-controlled key in Microsoft Partner Center allows an unauthorized attacker t...

CVE-2026-34327HIGH8.2same product

Externally controlled reference to a resource in another sphere in Microsoft Partner Center allows an unauthor...