CVE-2026-21515
Microsoft · Published April 23, 2026
9.9
CVSS v3.1
CRITICALPatch availableGet patch
Description
Azure IoT Central Elevation of Privilege Vulnerability. Exposure of sensitive information to an unauthorized actor in Azure IOT Central allows an authorized attacker to elevate privileges over a network.
Affected Products
- Azure IOT Central
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C