Junglewise Threat Intelligence

CVE-2026-83946: Microsoft Azure Portal stored cross-site scripting

CVE-2026-83946 · Severity: high · CVSS 8.2 · Published 2026-09-18

Vendors: Microsoft.

Executive brief

Azure Portal is the web interface used by Microsoft cloud customers to manage cloud infrastructure and services. An attacker could inject malicious code that executes in users' browsers, enabling account takeover, credential theft, or unauthorized changes to cloud resources without user awareness.

Technical details

Stored or reflected cross-site scripting (XSS) vulnerability in Azure Portal allows injection of untrusted input into web pages without proper sanitization. An attacker on the network can craft a malicious request or link that, when accessed by an authenticated user, executes arbitrary JavaScript in the victim's browser context, leading to session hijacking, credential harvesting, or malicious actions on cloud resources. Patches are available from Microsoft.

Affected products

  • Microsoft Azure Portal

Timeline

  • 2026-09-18: disclosed

References

Related threats