CVE-2026-23662 is a high-severity vulnerability (CVSS 7.5) affecting Microsoft Azure IoT Explorer, caused by missing authentication for a critical function. This flaw allows an unauthenticated attacker to remotely disclose sensitive information over a network with low attack complexity and no user interaction required. While there is no evidence of active exploitation and no public exploit code is available, the vulnerability has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.15.13CPE matchmatch criteria | cpe:2.3:a:microsoft:azure_iot_explorer:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.