CVSS 9.6 · CRITICAL
CVE-2026-24303
Improper access control in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network.
View on NVDAnalysis
Microsoft Partner Center contains a critical vulnerability allowing authenticated users to escalate privileges over the network. If your organization uses the Partner Center to manage Microsoft subscriptions, customers, or internal developer programs, be aware that this flaw could allow an attacker with standard access to gain unauthorized control over tenant management tools.
Severity
Score: 9.6(CRITICAL)
Vector:
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:NAV: NETWORK
AC: LOW
PR: LOW
UI: NONE
S: CHANGED
C: HIGH
I: HIGH
A: NONE
Weakness (CWE):
CWE-284EPSS
Probability of exploitation (next 30 days): 0.0006 (0.1%)
Percentile: 16.9%
EPSS: 2026-05-06
Affects
microsoft:partner_centerTechnical description
Improper access control in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network.
Published: 4/23/2026, 10:16:22 PM
Last modified: 4/28/2026, 12:11:27 PM