Skip to content
CVSS 9.6 · CRITICAL

CVE-2026-24303

Improper access control in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network.

View on NVD

Analysis

Microsoft Partner Center contains a critical vulnerability allowing authenticated users to escalate privileges over the network. If your organization uses the Partner Center to manage Microsoft subscriptions, customers, or internal developer programs, be aware that this flaw could allow an attacker with standard access to gain unauthorized control over tenant management tools.

Severity

Score: 9.6(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
AV: NETWORK
AC: LOW
PR: LOW
UI: NONE
S: CHANGED
C: HIGH
I: HIGH
A: NONE
Weakness (CWE): CWE-284

EPSS

Probability of exploitation (next 30 days): 0.0006 (0.1%)
Percentile: 16.9%
EPSS: 2026-05-06

Affects

microsoft:partner_center

Technical description

Improper access control in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network.

Published: 4/23/2026, 10:16:22 PM
Last modified: 4/28/2026, 12:11:27 PM

References

HomeEventsBlogResourcesTeam