CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2026-57100

CVSS 9.9v3.1pub. 2026-07-02upd. 2026-07-08

Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.

🤖 AI Analysis
How it works

The vulnerability classified as CWE-918 (SSRF) means that an attacker can force a server to execute network requests on their behalf to internal or external resources. In the case of the SyncFabric service, a logged-in user with basic privileges can, through crafted requests, trigger the execution of operations with higher privileges. The network attack vector without requiring user interaction (UI:N) and with changed scope (S:C) suggests that the impact may extend beyond the directly attacked component.

Impact

An attacker with access to an account can escalate their privileges in the Microsoft Entra environment, potentially gaining unauthorized access to internal resources, identity data, and compromising the confidentiality, integrity, and availability of the system at a critical level.

Mitigation & patch

Apply patches available from the vendor in accordance with references published by Microsoft Security Response Center at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57100

Who is affected

Microsoft Entra Provisioning Service (SyncFabric) — specific versions indicated in vendor references (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57100)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
  • Microsoft Entra Provisioning Service

    APP
    Microsoft
    all versions
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
SSRF
CWE
References

Related vulnerabilities

CVE-2026-59115CRITICAL9.9PL ✓same product

Path Traversal w Microsoft Entra Provisioning Service umożliwia eskalację uprawnień

CVE-2026-58644CRITICAL9.8⚠ KEVPL ✓same vendor

Zdalne wykonanie kodu poprzez deserializację w Microsoft SharePoint Server

CVE-2026-55040CRITICAL9.1⚠ KEVPL ✓same vendor

Obejście uwierzytelnienia w Microsoft SharePoint Server (RCE-ready)

CVE-2026-50522CRITICAL9.8⚠ KEVPL ✓same vendor

RCE przez deserializację niezaufanych danych w Microsoft SharePoint

CVE-2026-8398CRITICAL9.3⚠ KEVPL ✓same vendor

Atak na łańcuch dostaw DAEMON Tools Lite — trojanizacja instalatorów