CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2026-42901

CVSS 10.0v3.1pub. 2026-05-22upd. 2026-05-27

Origin validation error in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.

🤖 AI Analysis
How it works

The vulnerability results from a request origin validation error (CWE-346 — Origin Validation Error), meaning that Microsoft Entra ID incorrectly verifies the source of a network request. An attacker can send crafted requests that are treated as originating from a trusted source. This makes it possible to bypass access control mechanisms and obtain elevated privileges without possessing any credentials.

Impact

An unauthenticated attacker can obtain elevated privileges in the Microsoft Entra ID environment, potentially leading to full takeover of identities, resources, and service configuration beyond the original attack context (scope changed).

Mitigation & patch

Patches available from the vendor should be applied according to the references: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42901

Who is affected

Microsoft Entra ID — versions specified in the vendor's references

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
  • Microsoft Entra Id

    APP
    Microsoft
    all versions
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2026-69851CRITICAL9.9same product

Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileg...

CVE-2026-69836CRITICAL10.0same product

Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a...

CVE-2026-33843CRITICAL9.1PL ✓same product

Obejście uwierzytelnienia w Microsoft Azure Active Directory B2C

CVE-2026-40379CRITICAL9.3PL ✓same product

Ujawnienie wrażliwych danych w Azure Entra ID umożliwiające spoofing

CVE-2026-35431CRITICAL10.0PL ✓same product

SSRF w Microsoft Entra ID Entitlement Management umożliwia spoofing