CVE-2026-83711: Microsoft Entra
Critical severity, CVSS 10.0. EPSS: 0.8% chance of exploitation in the next 30 days.
Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.
Affected products
- Microsoft Entra: affected versions not specified
Published 2026-09-03. Last modified 2026-09-08.