AI analysis
Microsoft Azure Active Directory B2C contains a critical authorization flaw (CWE-639, authorization bypass through user-controlled key) in which access decisions rely on an identifier supplied by the caller without fully verifying that the caller is entitled to use it. An unauthenticated attacker can trigger the flaw remotely over a network with low attack complexity and no user interaction, per the CVSS vector (AV:N/AC:L/PR:N/UI:N/S:C). By supplying or tampering with the user-controlled key, the attacker bypasses authorization checks and elevates privileges, gaining high-impact access to data confidentiality and integrity (both rated High; availability is unaffected). All organizations using Azure AD B2C as their customer identity platform, and the end users behind those tenants, are potentially affected, since it is a Microsoft-hosted cloud service rather than customer-installed software. Per the September 2026 Security Update Review, the issue appears remediated through Microsoft's September 2026 update cycle; there is no public proof-of-concept, it is not in CISA's Known Exploited Vulnerabilities catalog, and EPSS estimates only a 0.6% chance of exploitation in the next 30 days.
What to do: Confirm via Microsoft's September 2026 advisory and your tenant's service health notifications that Azure AD B2C has received the fix; as a hosted service there is no customer-side version to install. Review tenant audit and sign-in logs for unexpected privilege changes or cross-user record access, and check custom policies and applications for authorization logic that trusts user-supplied identifiers (e.g., object IDs) without verification. Given the CVSS 10.0 rating, prioritize this validation now even though no in-the-wild exploitation or public PoC is known.
Affected
| Microsoft Azure Active Directory B2C | — |
Estimated exposure
massmillions+ of end users across all Azure AD B2C tenants (hosted service; every tenant potentially in scope) — Azure AD B2C is Microsoft's hosted customer identity and access management platform serving a large base of organizations and their customers, so rather than a count of installed products the entire multi-tenant end-user population,…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.