CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2026-33843

CVSS 9.1v3.1pub. 2026-05-22upd. 2026-05-27

Authentication bypass using an alternate path or channel in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.

🤖 AI Analysis
How it works

The vulnerability classified as CWE-288 (Authentication Bypass Using an Alternate Path or Channel) allows an attacker to gain access to a resource or system functionality by bypassing the standard authentication mechanism through an alternative path or channel. The attack can be conducted remotely over the network without requiring any prior privileges or victim engagement. Exploitation of the vulnerability allows the attacker to escalate privileges in the Azure Active Directory B2C environment.

Impact

An unauthorized attacker can obtain elevated privileges in the Azure Active Directory B2C environment, which may result in unauthorized access to protected resources and compromise of data confidentiality and integrity (high impact on C and I according to CVSS vector).

Mitigation & patch

Apply patches available from the vendor according to the references — detailed information about available fixes can be found in the Microsoft Security Response Center at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33843

Who is affected

Microsoft Azure Active Directory B2C — versions indicated in the vendor references (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33843)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  • Microsoft Entra Id

    APP
    Microsoft
    all versions
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2026-69851CRITICAL9.9same product

Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileg...

CVE-2026-69836CRITICAL10.0same product

Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a...

CVE-2026-42901CRITICAL10.0PL ✓same product

Błąd walidacji źródła w Microsoft Entra ID umożliwia privilege escalation

CVE-2026-40379CRITICAL9.3PL ✓same product

Ujawnienie wrażliwych danych w Azure Entra ID umożliwiające spoofing

CVE-2026-35431CRITICAL10.0PL ✓same product

SSRF w Microsoft Entra ID Entitlement Management umożliwia spoofing