Improper access control in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network.
The vulnerability consists of improper access control (CWE-284) in Microsoft Partner Center. An authenticated attacker with basic privileges can, without interaction from the victim, send a specially crafted network request that bypasses authorization mechanisms. As a result, it is possible to obtain privileges exceeding those the attacker is authorized for. The network attack vector and lack of attack complexity requirements significantly lower the threshold for conducting the attack.
An attacker can gain unauthorized access to resources and data of other users or organizations in Microsoft Partner Center, potentially compromising data confidentiality and integrity in multi-tenant environments (scope changed).
Patches available from the vendor should be applied in accordance with the references — details at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-24303
Microsoft Partner Center — versions indicated in vendor references
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:NMicrosoft Partner Center
APPMicrosoftall versions
Related vulnerabilities
Nieprawidłowa autoryzacja w Microsoft Partner Center — privilege escalation
Nieautoryzowana eskalacja uprawnień w Microsoft Partner Center
An improper access control vulnerability in Partner.Microsoft.com allows an a unauthenticated attacker to elev...
Authorization bypass through user-controlled key in Microsoft Partner Center allows an unauthorized attacker t...
Externally controlled reference to a resource in another sphere in Microsoft Partner Center allows an unauthor...