ZeroHour

CVE-2026-83711

mass

Unauthenticated Privilege Escalation via Authorization Bypass in Azure AD B2C

CVSS 3.1
10.0 critical
EPSS
<1%p46
Published
()
Modified
AI analysis

Microsoft Azure Active Directory B2C contains a critical authorization flaw (CWE-639, authorization bypass through user-controlled key) in which access decisions rely on an identifier supplied by the caller without fully verifying that the caller is entitled to use it. An unauthenticated attacker can trigger the flaw remotely over a network with low attack complexity and no user interaction, per the CVSS vector (AV:N/AC:L/PR:N/UI:N/S:C). By supplying or tampering with the user-controlled key, the attacker bypasses authorization checks and elevates privileges, gaining high-impact access to data confidentiality and integrity (both rated High; availability is unaffected). All organizations using Azure AD B2C as their customer identity platform, and the end users behind those tenants, are potentially affected, since it is a Microsoft-hosted cloud service rather than customer-installed software. Per the September 2026 Security Update Review, the issue appears remediated through Microsoft's September 2026 update cycle; there is no public proof-of-concept, it is not in CISA's Known Exploited Vulnerabilities catalog, and EPSS estimates only a 0.6% chance of exploitation in the next 30 days.

What to do: Confirm via Microsoft's September 2026 advisory and your tenant's service health notifications that Azure AD B2C has received the fix; as a hosted service there is no customer-side version to install. Review tenant audit and sign-in logs for unexpected privilege changes or cross-user record access, and check custom policies and applications for authorization logic that trusts user-supplied identifiers (e.g., object IDs) without verification. Given the CVSS 10.0 rating, prioritize this validation now even though no in-the-wild exploitation or public PoC is known.

Affected
Microsoft Azure Active Directory B2C
Estimated exposure
massmillions+ of end users across all Azure AD B2C tenants (hosted service; every tenant potentially in scope) — Azure AD B2C is Microsoft's hosted customer identity and access management platform serving a large base of organizations and their customers, so rather than a count of installed products the entire multi-tenant end-user population,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.

Weakness
CWE-639
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

In the news

The September 2026 Security Update Review

ZDI's September 2026 Microsoft update review lists two already-exploited Windows EoP zero-days and dozens of critical RCEs across Office, SQL Server, and Windows services.

The review catalogs Microsoft's September 2026 fixes, marking CVE-2026-85880 (Windows ALPC) and CVE-2026-81963 (Windows Update Stack) as already exploited elevation-of-privilege issues. It also lists critical RCE flaws in Office, Word, Excel, PowerPoint, Outlook, SQL Server, Windows DNS, DHCP and Failover Cluster, plus graphics component RCEs. Azure-side fixes include Entra ID, Copilot Studio, Azure AI Language and Azure AD B2C elevation-of-privilege flaws.