CyberICT

CVE-2026-23660

Microsoft · Published March 10, 2026

CVSS v3.1

HIGH
Patch availableGet patch

Description

Windows Admin Center in Azure Portal Elevation of Privilege Vulnerability. Improper access control in Azure Portal Windows Admin Center allows an authorized attacker to elevate privileges locally.

Affected Products

  • Windows Admin Center in Azure Portal

CVSS Vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C