CVE-2026-21531

Severity CVSS v4.0:
Pending analysis
Type:
CWE-502 Deserialization of Untrusted Dat
Publication date:
10/02/2026
Last modified:
12/02/2026

Description

Deserialization of untrusted data in Azure SDK allows an unauthorized attacker to execute code over a network.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:microsoft:azure_conversation_authoring_client_library:1.0.0:beta1:*:*:*:python:*:*
cpe:2.3:a:microsoft:azure_conversation_authoring_client_library:1.0.0:beta2:*:*:*:python:*:*
cpe:2.3:a:microsoft:azure_conversation_authoring_client_library:1.0.0:beta3:*:*:*:python:*:*


References to Advisories, Solutions, and Tools