Executive brief
A critical security flaw has been identified in Microsoft Azure Active Directory B2C, a service used to manage customer identities and access to applications. An unauthorized attacker could bypass security checks to gain elevated permissions within the system. This could allow an attacker to access sensitive customer data or perform administrative actions without proper authorization.
Technical details
A vulnerability classified as CWE-288 (Authentication Bypass Using an Alternate Path or Channel) exists in Microsoft Azure Active Directory B2C. The flaw allows an unauthenticated attacker to bypass standard authentication mechanisms by utilizing an alternate communication path or channel. This can be exploited remotely over the network without any user interaction. Successful exploitation enables the attacker to elevate their privileges, potentially gaining unauthorized access to sensitive resources or administrative functions. As this is an exclusively hosted service, Microsoft typically manages the deployment of fixes directly to the Azure environment.
Affected products
- Microsoft Azure Active Directory B2C
Timeline
- 2026-05-22: disclosed: Initial publication of the vulnerability by Microsoft.
- 2026-05-22: advisory: MSRC advisory published.