Junglewise Threat Intelligence

CVE-2026-42901: Microsoft Entra ID privilege escalation via origin validation error

CVE-2026-42901 · Severity: critical · CVSS 10 · Published 2026-05-22

Executive brief

A critical vulnerability has been identified in Microsoft Entra ID, the cloud-based identity and access management service used by organizations to manage user logins and permissions. An unauthorized attacker could exploit this flaw over the network to gain elevated administrative privileges. This could lead to a total compromise of the organization's identity infrastructure, allowing unauthorized access to sensitive data and cloud resources.

Technical details

Microsoft Entra ID is vulnerable to a privilege escalation flaw due to an origin validation error (CWE-346). The vulnerability allows a remote, unauthenticated attacker to bypass security boundaries and gain elevated permissions within the directory service. According to the CVSS 3.1 vector, the attack is low complexity, requires no user interaction, and has a 'Changed' scope, indicating the attacker can impact components beyond the immediate security scope of the vulnerable service. As this is an exclusively hosted service, Microsoft typically manages the deployment of fixes on the backend.

Affected products

  • Microsoft Entra ID

Timeline

  • 2026-05-22: disclosed
  • 2026-05-22: advisory: MSRC advisory published

References

Related threats