Executive brief
A critical vulnerability has been identified in Microsoft Entra ID, the cloud-based identity and access management service used by organizations to manage user logins and permissions. An unauthorized attacker could exploit this flaw over the network to gain elevated administrative privileges. This could lead to a total compromise of the organization's identity infrastructure, allowing unauthorized access to sensitive data and cloud resources.
Technical details
Microsoft Entra ID is vulnerable to a privilege escalation flaw due to an origin validation error (CWE-346). The vulnerability allows a remote, unauthenticated attacker to bypass security boundaries and gain elevated permissions within the directory service. According to the CVSS 3.1 vector, the attack is low complexity, requires no user interaction, and has a 'Changed' scope, indicating the attacker can impact components beyond the immediate security scope of the vulnerable service. As this is an exclusively hosted service, Microsoft typically manages the deployment of fixes on the backend.
Affected products
- Microsoft Entra ID
Timeline
- 2026-05-22: disclosed
- 2026-05-22: advisory: MSRC advisory published