Junglewise Threat Intelligence

CVE-2026-45480: Microsoft Azure Active Directory improper authentication privilege escalation

CVE-2026-45480 · Severity: critical · CVSS 10 · Published 2026-06-19

Executive brief

A critical security flaw has been identified in Microsoft's primary identity and access management service, Azure Active Directory. This vulnerability allows an unauthorized person to gain high-level administrative permissions over the network without needing a password or user interaction. If exploited, an attacker could take full control of an organization's cloud environment, potentially leading to total data theft, service disruption, and complete loss of administrative control.

Technical details

An improper authentication vulnerability (CWE-287) exists in Azure Active Directory (now Microsoft Entra ID). The flaw allows a remote, unauthenticated attacker to bypass security checks and elevate their privileges to a higher level, potentially gaining full administrative access. The attack vector is network-based and requires no user interaction or prior credentials. According to the CVSS 3.1 score of 10.0, the vulnerability has a 'Changed' scope, indicating that an exploit could impact resources beyond the identity provider itself, such as integrated cloud services and applications. Microsoft has addressed this in their hosted service environment.

Affected products

  • Microsoft Azure Active Directory (Entra ID) All versions

Timeline

  • 2026-06-19: disclosed
  • 2026-06-19: advisory: Microsoft published the security update guide entry.

References

Related threats