CVE-2026-35430Disclosure(microsoft / azure_privileged_identity_management)

MEDIUMCVSS 8.8 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch microsoft azure_privileged_identity_management systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Authorization bypass through user-controlled key in Azure Privileged Identity Management (PIM) allows an authorized attacker to elevate privileges over a network.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • azure_privileged_identity_management

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-05-23); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
azure_privileged_identity_management

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-23: 1Mentions · 2026-05-25: 1Active Exploitation · 2026-05-25: 1Patch / Workaround · 2026-05-25: 1Technical Details · 2026-05-23: 105-2305-25
Signal classification2 categories
Disclosure
150.0%
Active Exploitation
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-05-231
Disclosure1
2026-05-251
Active Exploitation1
Full discourse2 posts
  • NerdieNews@NewsNerdie
    Active Exploitation

    ⚠️ CVE-2026-35430 in Azure PIM is being exploited by attackers to elevate privileges, potentially compromising sensitive accounts. Patch immediately to prevent breaches. #NerdieNews #CyberSecurity #Vulnerability https://t.co/g9iKCXUjr1

    Post summary

    The tweet reports that CVE‑2026‑35430 in Azure PIM is currently being exploited for privilege escalation and urges users to patch immediately to mitigate the risk.

    0000037
    64 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-35430 Authorization bypass through user-controlled key in Azure Privileged Identity Management (PIM) allows an authorized attacker to elevate privileges over a network. https://www.cve.org/CVERecord?id=CVE-2026-35430

    Post summary

    An announcement of CVE‑2026‑35430, describing an authorization bypass in Azure PIM that permits privilege escalation, with no PoC, exploit code, or patch information included.

    00000185
    57.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftazure_privileged_identity_management---

Explore more