Junglewise Threat Intelligence

CVE-2026-50653: Microsoft Azure Active Directory infinite loop denial of service

CVE-2026-50653 · Severity: high · CVSS 7.5 · Published 2026-07-14

Executive brief

Microsoft Azure Active Directory, a cloud-based identity and access management service, is vulnerable to a flaw that could allow an attacker to disrupt the service. By sending specific network requests, an unauthorized user can trigger an infinite loop that consumes system resources, leading to a denial of service. This could prevent legitimate users from logging into their accounts or accessing corporate applications.

Technical details

A denial of service vulnerability exists in Microsoft Azure Active Directory due to an infinite loop (CWE-835) caused by a loop with an unreachable exit condition. An unauthenticated attacker can exploit this over the network by sending specially crafted requests to the service, leading to uncontrolled resource consumption (CWE-400). The vulnerability affects Azure Active Directory 2021 versions prior to 8.19.2. Successful exploitation results in a complete loss of availability for the affected service component. Microsoft has addressed this issue in version 8.19.2.

Affected products

  • Microsoft Azure Active Directory 2021 < 8.19.2

Timeline

  • 2026-07-14: advisory: Microsoft published the security advisory.
  • 2026-07-14: patched: Fix available in version 8.19.2.

References

Related threats