CyberICT

CVE-2026-23663

Microsoft · Published May 21, 2026

CVSS v3.1

HIGH
Patch availableGet patch

Description

Microsoft Global Secure Access (GSA) Information Disclosure Vulnerability. Improper privilege management in Azure Entra ID allows an unauthorized attacker to elevate privileges over a network.

Affected Products

  • Microsoft Global Secure Access (GSA)

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C