VYPR

Azure Active Directory B2C

by Microsoft

CVEs (7)

  • CVE-2026-83711CriSep 3, 2026
    risk 0.65cvss 10.0epss 0.01

    Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-33843CriMay 22, 2026
    risk 0.59cvss 9.1epss 0.00

    Authentication bypass using an alternate path or channel in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2024-21381MedFeb 13, 2024
    risk 0.44cvss 6.8epss 0.00

    Microsoft Azure Active Directory B2C Spoofing Vulnerability

  • CVE-2023-36871MedJul 11, 2023
    risk 0.42cvss 6.5epss 0.01

    Azure Active Directory Security Feature Bypass Vulnerability

  • CVE-2019-1172MedAug 14, 2019
    risk 0.28cvss 4.3epss 0.04

    An information disclosure vulnerability exists in Azure Active Directory (AAD) Microsoft Account (MSA) during the login request session. An attacker who successfully exploited the vulnerability could take over a user's account. To exploit the vulnerability, an attacker would…

  • CVE-2026-50653HigJul 14, 2026
    risk 0.00cvss 7.5epss 0.01

    Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network.

  • CVE-2026-50652HigJul 14, 2026
    risk 0.00cvss 7.5epss 0.02

    Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network.