Junglewise Threat Intelligence

CVE-2026-23663: Microsoft Azure Entra ID privilege escalation

CVE-2026-23663 · Severity: high · CVSS 7.5 · Published 2026-05-22

Technologies: Microsoft Entra ID. Vendors: Microsoft.

Executive brief

Microsoft Entra ID (formerly Azure AD), the primary identity and access management service for Microsoft cloud environments, contains a vulnerability that could allow an unauthorized user to gain higher-level permissions. An attacker could exploit this over the network to access sensitive information they are not authorized to see. This poses a risk to the integrity of organizational access controls and the confidentiality of user data.

Technical details

A privilege escalation vulnerability exists in Microsoft Entra ID due to improper privilege management (CWE-269). The flaw allows an unauthenticated attacker to elevate their permissions via a network-based attack vector without requiring user interaction. According to the CVSS vector, the exploit results in high confidentiality impact but does not directly impact integrity or availability. As Entra ID is an exclusively hosted cloud service, Microsoft typically manages the deployment of fixes on the backend.

Affected products

  • Microsoft Entra ID

Timeline

  • 2026-05-22: disclosed
  • 2026-05-22: advisory

References

Related threats