EXPOSURES › CVE-2026-33843
CVE-2026-33843
CRITICAL
DETAIL
SourceNVD · cve
Published2026-05-22
CVSS9.1
Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-33843 ↗
▸ RECOMMENDED ACTION Critical severity — schedule patching of the affected products.
PLAYERS IMPLICATED
DESCRIPTION
Authentication bypass using an alternate path or channel in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.
AFFECTED FEDRAMP PRODUCTS · 4
| PRODUCT | STATUS |
|---|---|
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |