CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2026-40379

CVSS 9.3v3.1pub. 2026-05-12upd. 2026-05-21

Exposure of sensitive information to an unauthorized actor in Azure Entra ID allows an unauthorized attacker to perform spoofing over a network.

🤖 AI Analysis
How it works

A vulnerability classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) involves improper disclosure of sensitive information by the Azure Entra ID service. An attacker without any permissions can remotely, with minimal user interaction, access this data and use it to impersonate another entity (spoofing). The network attack vector and lack of required permissions on the attacker's side make the vulnerability easy to exploit at scale.

Impact

An attacker can gain access to sensitive information from Azure Entra ID and conduct a spoofing attack, potentially impersonating an authorized user or system, which threatens the confidentiality and integrity of the identity environment.

Mitigation & patch

Apply patches available from the vendor according to references: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40379. It is recommended to continuously monitor the Microsoft Security Response Center to track updates.

Who is affected

Azure Entra ID — versions indicated in vendor references (Microsoft Security Response Center).

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
  • Microsoft Entra Id

    APP
    Microsoft
    all versions
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2026-69836CRITICAL10.0same product

Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a...

CVE-2026-69851CRITICAL9.9same product

Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileg...

CVE-2026-42901CRITICAL10.0PL ✓same product

Błąd walidacji źródła w Microsoft Entra ID umożliwia privilege escalation

CVE-2026-33843CRITICAL9.1PL ✓same product

Obejście uwierzytelnienia w Microsoft Azure Active Directory B2C

CVE-2026-35431CRITICAL10.0PL ✓same product

SSRF w Microsoft Entra ID Entitlement Management umożliwia spoofing