Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.
The vulnerability classified as CWE-918 (SSRF) means that an attacker can force a server to execute network requests on their behalf to internal or external resources. In the case of the SyncFabric service, a logged-in user with basic privileges can, through crafted requests, trigger the execution of operations with higher privileges. The network attack vector without requiring user interaction (UI:N) and with changed scope (S:C) suggests that the impact may extend beyond the directly attacked component.
An attacker with access to an account can escalate their privileges in the Microsoft Entra environment, potentially gaining unauthorized access to internal resources, identity data, and compromising the confidentiality, integrity, and availability of the system at a critical level.
Apply patches available from the vendor in accordance with references published by Microsoft Security Response Center at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57100
Microsoft Entra Provisioning Service (SyncFabric) — specific versions indicated in vendor references (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-57100)
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:HMicrosoft Entra Provisioning Service
APPMicrosoftall versions
Related vulnerabilities
Path Traversal w Microsoft Entra Provisioning Service umożliwia eskalację uprawnień
Zdalne wykonanie kodu poprzez deserializację w Microsoft SharePoint Server
Obejście uwierzytelnienia w Microsoft SharePoint Server (RCE-ready)
RCE przez deserializację niezaufanych danych w Microsoft SharePoint
Atak na łańcuch dostaw DAEMON Tools Lite — trojanizacja instalatorów