{"api_version":"1","generated_at":"2026-07-23T13:07:09+00:00","cve":"CVE-2026-33117","urls":{"html":"https://cve.report/CVE-2026-33117","api":"https://cve.report/api/cve/CVE-2026-33117.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-33117","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-33117"},"summary":{"title":"Azure SDK for Java Security Feature Bypass Vulnerability","description":"The Java Key Vault Keys library in the Azure SDK for Java contains an issue in the local cryptographic verification path where authentication tag comparison was implemented incorrectly. In affected applications that use the vulnerable local cryptography path, specially crafted encrypted input may bypass integrity verification checks. Operations delegated to the Key Vault service are not affected. The issue is addressed in version 4.10.6.","state":"PUBLISHED","assigner":"microsoft","published_at":"2026-05-12 18:17:04","updated_at":"2026-05-15 18:38:17"},"problem_types":["CWE-287","CWE-347","CWE-287 CWE-287: Improper Authentication","CWE-347 CWE-347: Improper Verification of Cryptographic Signature"],"metrics":[{"version":"3.1","source":"secure@microsoft.com","type":"Primary","score":"9.1","severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","baseScore":9.1,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"9.1","severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C","data":{"baseScore":9.1,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C","version":"3.1"}}],"references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33117","name":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33117","refsource":"secure@microsoft.com","tags":["Vendor Advisory"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-33117","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-33117","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Microsoft","product":"Azure SDK for Java","version":"affected 1.0.0 4.10.6 custom","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2026","cve_id":"33117","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"azure_sdk_for_java","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"33117","cve":"CVE-2026-33117","epss":"0.000300000","percentile":"0.090160000","score_date":"2026-05-28","updated_at":"2026-05-29 00:13:16"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-33117","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"total"}],"role":"CISA Coordinator","timestamp":"2026-05-13T03:57:37.128659Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-05-13T10:17:55.151Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"product":"Azure SDK for Java","vendor":"Microsoft","versions":[{"lessThan":"4.10.6","status":"affected","version":"1.0.0","versionType":"custom"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:a:microsoft:azure_sdk_for_java:*:*:*:*:*:*:*:*","versionEndExcluding":"4.10.6","versionStartIncluding":"1.0.0","vulnerable":true}],"negate":false,"operator":"OR"}]}],"datePublic":"2026-05-12T14:00:00.000Z","descriptions":[{"lang":"en-US","value":"The Java Key Vault Keys library in the Azure SDK for Java contains an issue in the local cryptographic verification path where authentication tag comparison was implemented incorrectly. In affected applications that use the vulnerable local cryptography path, specially crafted encrypted input may bypass integrity verification checks. Operations delegated to the Key Vault service are not affected. The issue is addressed in version 4.10.6."}],"metrics":[{"cvssV3_1":{"baseScore":9.1,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en-US","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-287","description":"CWE-287: Improper Authentication","lang":"en-US","type":"CWE"},{"cweId":"CWE-347","description":"CWE-347: Improper Verification of Cryptographic Signature","lang":"en-US","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-05-22T22:04:42.608Z","orgId":"f38d906d-7342-40ea-92c1-6c4a2c6478c8","shortName":"microsoft"},"references":[{"name":"Azure SDK for Java Security Feature Bypass Vulnerability","tags":["vendor-advisory","patch"],"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33117"}],"title":"Azure SDK for Java Security Feature Bypass Vulnerability"}},"cveMetadata":{"assignerOrgId":"f38d906d-7342-40ea-92c1-6c4a2c6478c8","assignerShortName":"microsoft","cveId":"CVE-2026-33117","datePublished":"2026-05-12T16:58:17.299Z","dateReserved":"2026-03-17T20:15:23.721Z","dateUpdated":"2026-05-22T22:04:42.608Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-05-12 18:17:04","lastModifiedDate":"2026-05-15 18:38:17","problem_types":["CWE-287","CWE-347","CWE-287 CWE-287: Improper Authentication","CWE-347 CWE-347: Improper Verification of Cryptographic Signature"],"metrics":{"cvssMetricV31":[{"source":"secure@microsoft.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","baseScore":9.1,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":5.2}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:azure_sdk_for_java:*:*:*:*:*:*:*:*","versionEndExcluding":"4.10.6","matchCriteriaId":"45101624-5AAF-48EF-8188-E4AB088A49C2"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"33117","Ordinal":"1","Title":"Azure SDK for Java Security Feature Bypass Vulnerability","CVE":"CVE-2026-33117","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"33117","Ordinal":"1","NoteData":"Improper authentication in Azure SDK allows an unauthorized attacker to bypass a security feature over a network.","Type":"Description","Title":"Azure SDK for Java Security Feature Bypass Vulnerability"}]}}}