Executive brief
Microsoft Partner Center is a web-based portal used by partners and resellers to manage customer accounts, subscriptions, and billing. An authorization bypass vulnerability allows unauthenticated attackers to access sensitive information such as customer data and account details through a user-controlled cryptographic key, potentially exposing confidential business and customer information to unauthorized parties.
Technical details
This authorization bypass vulnerability in Microsoft Partner Center stems from improper validation of a user-controlled cryptographic key used in authentication or access control logic. An attacker can craft a malicious request with a specially crafted key value to bypass authorization checks and gain unauthorized access to sensitive information. The vulnerability is network-accessible and requires no authentication or user interaction. Successful exploitation allows attackers to disclose confidential information including customer data, subscription details, and account information. Microsoft has issued security updates to patch this vulnerability.
Affected products
- Microsoft Partner Center <unknown>
Timeline
- 2026-08-20: disclosed