CVE-2026-33843
Microsoft · Published May 21, 2026
9.1
CVSS v3.1
CRITICALPatch availableGet patch
Description
Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerability. Authentication bypass using an alternate path or channel in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.
Affected Products
- Microsoft Entra ID
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N