Junglewise Threat Intelligence

CVE-2026-84003: Microsoft Authentication Library authentication bypass in MSAL for Node.js

CVE-2026-84003 · Severity: high · CVSS 7.4 · Published 2026-09-08

Executive brief

Microsoft Authentication Library (MSAL) for Node.js is used by applications to securely authenticate users and obtain access tokens. A capture-replay authentication bypass vulnerability allows an attacker to impersonate legitimate users and perform unauthorized actions, potentially compromising any system relying on MSAL for authentication.

Technical details

The vulnerability is an authentication bypass in MSAL for Node.js that exploits capture-replay attack techniques. An attacker can intercept and replay authentication tokens or credentials to bypass the authentication mechanism and assume the identity of a legitimate user. The attack is network-based and does not require prior authentication or special privileges. This vulnerability allows an attacker to spoof user identity and gain unauthorized access to protected resources. A patch is expected to be available from Microsoft.

Affected products

  • Microsoft Authentication Library (MSAL) for Node.js

Timeline

  • 2026-09-08: disclosed

References