CyberICT

CVE-2026-33843

Microsoft · Published May 21, 2026

CVSS v3.1

CRITICAL
Patch availableGet patch

Description

Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerability. Authentication bypass using an alternate path or channel in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.

Affected Products

  • Microsoft Entra ID

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N