PatchDayAlert

CVE

CVE-2026-57104

0field notes · 1digest CVSS 8.8

The verdict

An XSS vulnerability in Azure Storage Explorer lets an unauthenticated attacker escalate privileges over the network. If someone opens crafted content in Storage Explorer, the attacker can potentially run actions with the victim's Azure permissions. No prior authentication is required on the attacker's side, which makes this worse than a typical XSS.

Patch urgency · Patch within 24 hours


Daily digests