CVE-2026-23663Disclosure(microsoft / global_secure_access)

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper privilege management in Azure Entra ID allows an unauthorized attacker to elevate privileges over a network.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • global_secure_access

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-05-27)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
global_secure_access

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-05-23: 1Mentions · 2026-05-27: 2Technical Details · 2026-05-23: 1Technical Details · 2026-05-27: 205-2305-27
Signal classification1 categories
Disclosure
3100.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-231
Disclosure1
2026-05-272
Disclosure2
Full discourse3 posts
  • DailyCVE@dailycve
    Disclosure

    🔴 #Azure Entra ID, Improper Privilege Management, #CVE-2026-23663 (High) https://dailycve.com/azure-entra-id-improper-privilege-management-cve-2026-23663-high/

    Post summary

    The tweet announces CVE-2026-23663, an Improper Privilege Management flaw in Azure Entra ID with high severity, but offers no detail on exploitation or mitigation.

    0000045
    207 followersView on X
  • DFIR Lab@DFIR_Lab
    Disclosure

    🚨 HIGH SEVERITY: CVE-2026-23663 (CVSS 7.5) Azure Entra ID privilege escalation vulnerability allows unauthorized network-based attacks. Improper privilege management (CWE-269) enables attackers to elevate privileges remotely. #CVE #Vulnerability #PatchNow https://t.co/LMi6fWUQg0

    Post summary

    The tweet discloses a high‑severity CVE‑2026‑23663 in Azure Entra ID, describing a privilege escalation flaw, but omits PoC, exploit code, or patch details.

    0000060
    30 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-23663 Improper privilege management in Azure Entra ID allows an unauthorized attacker to elevate privileges over a network. https://www.cve.org/CVERecord?id=CVE-2026-23663

    Post summary

    A new CVE (CVE-2026-23663) has been identified in Azure Entra ID, detailing improper privilege management that could let an attacker elevate privileges across the network.

    00000158
    57.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftglobal_secure_access---

Explore more