Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
7.5

Azure IoT Explorer: Critical Information Disclosure via Missing Authentication

CVE-2026-23662
Summary

An issue in Azure IoT Explorer allows unauthorized users to access sensitive information. This could happen if an attacker can access the network where the IoT Explorer is installed. To fix this, update your Azure IoT Explorer to the latest version if available.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versionsFix available
microsoft azure_iot_explorer <= 0.15.13 –
Original title
Missing authentication for critical function in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network.
Original description
Missing authentication for critical function in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network.
nvd CVSS3.1 7.5
Vulnerability type
CWE-306 Missing Authentication for Critical Function
CWE-319 Cleartext Transmission of Sensitive Information
Published: 10 Mar 2026 · Updated: 14 Mar 2026 · First seen: 11 Mar 2026