9.8
CVE-2026-33843
- EPSS 0.47%
- Veröffentlicht 22.05.2026 22:03:10
- Zuletzt bearbeitet 23.07.2026 11:10:00
- Erkennungen
Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerability
Authentication bypass using an alternate path or channel in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.47% | 0.372 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| Microsoft | 9.1 | 3.9 | 5.2 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
|
CWE-288 Authentication Bypass Using an Alternate Path or Channel
The product requires authentication, but the product has an alternate path or channel that does not require authentication.
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33843