CVE-2026-23664: Azure IoT Explorer Information Disclosure Vulnerability

Overview

Severity
High (CVSS 7.5)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
Category
Information Disclosure
Exploit Status
Not Exploited
Exploitation Likelihood
Less Likely
Patch Tuesday
2026-Mar
Released
2026-03-10
EPSS Score
0.07% (percentile: 22.4%)

Description

Improper restriction of communication channel to intended endpoints in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network.

FAQ

What type of information could be disclosed by this vulnerability? This vulnerability could allow an attacker with network access to the exposed Azure IoT Explorer API port to view sensitive data that the application makes available without authentication. Depending on how the application is used, this may include file contents from the host system, directory listings, IoT device data or configuration details, and metadata retrieved through server-side request forgery (SSRF), such as Azure Instance Metadata Service (IMDS) information.

Affected Products (1)

Azure

  • Azure IoT Explorer

Security Updates (2)

Acknowledgments

<a href="https://www.linkedin.com/in/hay-mizrachi/">Hay Mizrachi</a> with <a href="https://microsoft.com/">Microsoft</a>

Revision History

  • 2026-03-10: Information published.