CVE-2026-33843
A critical flaw in Microsoft Entra ID (Azure AD B2C) lets attackers bypass authentication by using an alternate path, giving them elevated privileges over a network. The vulnerability can be exploited without any user interaction or special permissions. It is a serious risk for any organization using Azure AD B2C.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Microsoft Entra ID (Azure AD B2C) – all versions listed in the CPE entry.
Real-world impact
An attacker could gain higher-level access to Azure AD B2C resources, potentially accessing or modifying sensitive data, impersonating users, or taking control of the directory.
Why this severity
The CVSS score of 9.1 reflects that the flaw can be exploited remotely over the network, requires no authentication or user interaction, and gives the attacker full control over the system. The low attack complexity and lack of required privileges make it highly dangerous.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources
Timeline
- May 22, 2026 · May 22, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 23, 2026 · 12d agoAdvisory updatedThe NVD record was last revised.
How it’s attacked
References & advisories
- msrc.microsoft.com/update-guide/vulnerability/…vendor advisory