Authentication bypass using an alternate path or channel in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.
The vulnerability classified as CWE-288 (Authentication Bypass Using an Alternate Path or Channel) allows an attacker to gain access to a resource or system functionality by bypassing the standard authentication mechanism through an alternative path or channel. The attack can be conducted remotely over the network without requiring any prior privileges or victim engagement. Exploitation of the vulnerability allows the attacker to escalate privileges in the Azure Active Directory B2C environment.
An unauthorized attacker can obtain elevated privileges in the Azure Active Directory B2C environment, which may result in unauthorized access to protected resources and compromise of data confidentiality and integrity (high impact on C and I according to CVSS vector).
Apply patches available from the vendor according to the references — detailed information about available fixes can be found in the Microsoft Security Response Center at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33843
Microsoft Azure Active Directory B2C — versions indicated in the vendor references (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33843)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NMicrosoft Entra Id
APPMicrosoftall versions
Related vulnerabilities
Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileg...
Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a...
Błąd walidacji źródła w Microsoft Entra ID umożliwia privilege escalation
Ujawnienie wrażliwych danych w Azure Entra ID umożliwiające spoofing
SSRF w Microsoft Entra ID Entitlement Management umożliwia spoofing