Azure Active Directory B2C
by Microsoft
CVEs (7)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-83711 | Cri | 0.65 | 10.0 | 0.01 | Sep 3, 2026 | Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2026-33843 | Cri | 0.59 | 9.1 | 0.00 | May 22, 2026 | Authentication bypass using an alternate path or channel in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2024-21381 | Med | 0.44 | 6.8 | 0.00 | Feb 13, 2024 | Microsoft Azure Active Directory B2C Spoofing Vulnerability | ||
| CVE-2023-36871 | Med | 0.42 | 6.5 | 0.01 | Jul 11, 2023 | Azure Active Directory Security Feature Bypass Vulnerability | ||
| CVE-2019-1172 | Med | 0.28 | 4.3 | 0.04 | Aug 14, 2019 | An information disclosure vulnerability exists in Azure Active Directory (AAD) Microsoft Account (MSA) during the login request session. An attacker who successfully exploited the vulnerability could take over a user's account. To exploit the vulnerability, an attacker would… | ||
| CVE-2026-50653 | Hig | 0.00 | 7.5 | 0.01 | Jul 14, 2026 | Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network. | ||
| CVE-2026-50652 | Hig | 0.00 | 7.5 | 0.02 | Jul 14, 2026 | Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network. |
- risk 0.65cvss 10.0epss 0.01
Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.
- risk 0.59cvss 9.1epss 0.00
Authentication bypass using an alternate path or channel in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.
- risk 0.44cvss 6.8epss 0.00
Microsoft Azure Active Directory B2C Spoofing Vulnerability
- risk 0.42cvss 6.5epss 0.01
Azure Active Directory Security Feature Bypass Vulnerability
- risk 0.28cvss 4.3epss 0.04
An information disclosure vulnerability exists in Azure Active Directory (AAD) Microsoft Account (MSA) during the login request session. An attacker who successfully exploited the vulnerability could take over a user's account. To exploit the vulnerability, an attacker would…
- risk 0.00cvss 7.5epss 0.01
Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network.
- risk 0.00cvss 7.5epss 0.02
Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network.