Junglewise Threat Intelligence

CVE-2026-83711: Microsoft Azure Active Directory B2C authorization bypass in user-controlled key

CVE-2026-83711 · Severity: critical · CVSS 10 · Published 2026-09-03

Vendors: Microsoft.

Executive brief

Azure Active Directory B2C is Microsoft's cloud-based identity and access management service used by organizations to manage customer identities and authentication. This vulnerability allows an attacker to bypass authorization checks by manipulating a user-controlled cryptographic key, enabling unauthorized privilege escalation across networked systems without authentication. This could allow attackers to gain administrative access to customer accounts and data protected by this service.

Technical details

The vulnerability is an authorization bypass in Microsoft Azure Active Directory B2C caused by improper validation of a user-controlled cryptographic key. An attacker can exploit this over the network without requiring prior authentication by crafting a malicious key to bypass authorization controls and elevate privileges. The flaw stems from inadequate input validation or cryptographic key handling in the B2C authentication flow. Successful exploitation allows an attacker to gain unauthorized access and elevated privileges. A patch is available from Microsoft via their Security Response Center.

Affected products

  • Microsoft Azure Active Directory B2C

Timeline

  • 2026-09-03: disclosed

References

Related threats