Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
7.5
Azure IoT Explorer: Critical Information Disclosure via Missing Authentication
CVE-2026-23662
Summary
An issue in Azure IoT Explorer allows unauthorized users to access sensitive information. This could happen if an attacker can access the network where the IoT Explorer is installed. To fix this, update your Azure IoT Explorer to the latest version if available.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions | Fix available |
|---|---|---|---|
| microsoft | azure_iot_explorer | <= 0.15.13 | – |
Original title
Missing authentication for critical function in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network.
Original description
Missing authentication for critical function in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network.
nvd CVSS3.1
7.5
Vulnerability type
CWE-306
Missing Authentication for Critical Function
CWE-319
Cleartext Transmission of Sensitive Information
Published: 10 Mar 2026 · Updated: 14 Mar 2026 · First seen: 11 Mar 2026