Junglewise Threat Intelligence

CVE-2026-40379: Microsoft Entra ID information disclosure and spoofing

CVE-2026-40379 · Severity: critical · CVSS 9.3 · Published 2026-05-12

Technologies: Microsoft Entra ID. Vendors: Microsoft.

Executive brief

A critical vulnerability in Microsoft Entra ID (formerly Azure AD) could allow an unauthorized attacker to steal sensitive information and impersonate legitimate users. Entra ID is the primary identity and access management service for Microsoft cloud environments; a successful exploit could lead to unauthorized access to corporate resources and data. This issue primarily involves the exposure of sensitive data that enables network-based spoofing attacks.

Technical details

Microsoft Entra ID is vulnerable to an information disclosure (CWE-200) that facilitates network-based spoofing. The vulnerability allows an unauthenticated attacker to access sensitive data, which can then be used to impersonate users or services. According to the CVSS vector, the attack requires user interaction (UI:R) and results in a scope change (S:C), impacting both confidentiality and integrity. As an exclusively hosted service, Microsoft typically manages the remediation on the backend, though administrators should monitor for suspicious authentication patterns.

Affected products

  • Microsoft Entra ID All versions (Exclusively Hosted Service)

Timeline

  • 2026-05-12: disclosed: Initial publication by Microsoft Corporation
  • 2026-05-12: advisory: Microsoft Security Response Center advisory published

References

Related threats