Skip to main content

CVE-2026-83711

Microsoft Azure Active Directory B2C Elevation of Privilege vulnerability

Microsoft

MSRC advisory September 3, 2026

Alert details

Source feed
Microsoft MSRC
CVE ID
CVE-2026-83711
Affected products
Microsoft Azure Active Directory B2C Elevation of Privilege · Microsoft Microsoft Azure Active Directory B2C Elevation of Privilege · Microsoft

What happened

<p>Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.</p>

What it means for your business

Microsoft Azure Active Directory B2C Elevation of Privilege vulnerability (CVE-2026-83711) was added to Microsoft’s security update guidance. <p>Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.

Sources

Related briefs

LowMicrosoft MSRC

CVE-2026-84359

Information leak in Skia in Microsoft Edge vulnerability

Information leak in Skia in Microsoft Edge vulnerability (CVE-2026-84359) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-84358

Improper privilege management in Downloads in Microsoft Edge vulnerability

Improper privilege management in Downloads in Microsoft Edge vulnerability (CVE-2026-84358) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.

MediumMicrosoft MSRC

CVE-2026-84357

Improper input validation in Omnibox in Microsoft Edge vulnerability

Improper input validation in Omnibox in Microsoft Edge vulnerability (CVE-2026-84357) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.

MediumMicrosoft MSRC

CVE-2026-84356

UI misrepresentation in FullScreen in Microsoft Edge vulnerability

UI misrepresentation in FullScreen in Microsoft Edge vulnerability (CVE-2026-84356) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.

Need help patching?

PremierePC monitors KEV alerts for managed clients and helps teams prioritize remediation before attackers do.