Exposure of sensitive information to an unauthorized actor in Azure Entra ID allows an unauthorized attacker to perform spoofing over a network.
A vulnerability classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) involves improper disclosure of sensitive information by the Azure Entra ID service. An attacker without any permissions can remotely, with minimal user interaction, access this data and use it to impersonate another entity (spoofing). The network attack vector and lack of required permissions on the attacker's side make the vulnerability easy to exploit at scale.
An attacker can gain access to sensitive information from Azure Entra ID and conduct a spoofing attack, potentially impersonating an authorized user or system, which threatens the confidentiality and integrity of the identity environment.
Apply patches available from the vendor according to references: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40379. It is recommended to continuously monitor the Microsoft Security Response Center to track updates.
Azure Entra ID — versions indicated in vendor references (Microsoft Security Response Center).
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:NMicrosoft Entra Id
APPMicrosoftall versions
Related vulnerabilities
Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a...
Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileg...
Błąd walidacji źródła w Microsoft Entra ID umożliwia privilege escalation
Obejście uwierzytelnienia w Microsoft Azure Active Directory B2C
SSRF w Microsoft Entra ID Entitlement Management umożliwia spoofing