CyberICT

CVE-2026-21515

Microsoft · Published April 23, 2026

CVSS v3.1

CRITICAL
Patch availableGet patch

Description

Azure IoT Central Elevation of Privilege Vulnerability. Exposure of sensitive information to an unauthorized actor in Azure IOT Central allows an authorized attacker to elevate privileges over a network.

Affected Products

  • Azure IOT Central

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C