Skip to content
CVSS 9.9 · CRITICAL

CVE-2026-21515

Exposure of sensitive information to an unauthorized actor in Azure IOT Central allows an authorized attacker to elevate privileges over a network.

View on NVD

Analysis

Microsoft Azure IoT Central has a critical vulnerability allowing for privilege escalation via sensitive information exposure. Organizations using this SaaS platform for IoT device management should review their environments immediately, as an attacker can gain elevated permissions over the network.

Severity

Score: 9.9(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
AV: NETWORK
AC: LOW
PR: LOW
UI: NONE
S: CHANGED
C: HIGH
I: HIGH
A: HIGH
Weakness (CWE): CWE-200

EPSS

Probability of exploitation (next 30 days): 0.0010 (0.1%)
Percentile: 27.5%
EPSS: 2026-05-06

Affects

microsoft:azure_iot_central

Technical description

Exposure of sensitive information to an unauthorized actor in Azure IOT Central allows an authorized attacker to elevate privileges over a network.

Published: 4/24/2026, 1:16:03 PM
Last modified: 4/27/2026, 7:41:24 PM

References

HomeEventsBlogResourcesTeam