Executive brief
Azure Active Directory B2C is Microsoft's cloud-based identity and access management service used by organizations to manage customer identities and authentication. This vulnerability allows an attacker to bypass authorization checks by manipulating a user-controlled cryptographic key, enabling unauthorized privilege escalation across networked systems without authentication. This could allow attackers to gain administrative access to customer accounts and data protected by this service.
Technical details
The vulnerability is an authorization bypass in Microsoft Azure Active Directory B2C caused by improper validation of a user-controlled cryptographic key. An attacker can exploit this over the network without requiring prior authentication by crafting a malicious key to bypass authorization controls and elevate privileges. The flaw stems from inadequate input validation or cryptographic key handling in the B2C authentication flow. Successful exploitation allows an attacker to gain unauthorized access and elevated privileges. A patch is available from Microsoft via their Security Response Center.
Affected products
- Microsoft Azure Active Directory B2C
Timeline
- 2026-09-03: disclosed