CVE-2026-23663
Microsoft · Published May 21, 2026
7.5
CVSS v3.1
HIGHPatch availableGet patch
Description
Microsoft Global Secure Access (GSA) Information Disclosure Vulnerability. Improper privilege management in Azure Entra ID allows an unauthorized attacker to elevate privileges over a network.
Affected Products
- Microsoft Global Secure Access (GSA)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C