Vulnerabilities (CVE)

Filtered by vendor Microsoft Subscribe
Filtered by product Entra Id
Total 9 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-33843 1 Microsoft 1 Entra Id 2026-05-27 N/A 9.1 CRITICAL
Authentication bypass using an alternate path or channel in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-42901 1 Microsoft 1 Entra Id 2026-05-27 N/A 10.0 CRITICAL
Origin validation error in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-40379 1 Microsoft 1 Entra Id 2026-05-21 N/A 9.3 CRITICAL
Exposure of sensitive information to an unauthorized actor in Azure Entra ID allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-35431 1 Microsoft 1 Entra Id 2026-04-28 N/A 10.0 CRITICAL
Server-side request forgery (ssrf) in Microsoft Entra ID Entitlement Management allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-24305 1 Microsoft 1 Entra Id 2026-02-03 N/A 9.3 CRITICAL
Azure Entra ID Elevation of Privilege Vulnerability
CVE-2025-59218 1 Microsoft 1 Entra Id 2025-10-16 N/A 9.6 CRITICAL
Azure Entra ID Elevation of Privilege Vulnerability
CVE-2025-59246 1 Microsoft 1 Entra Id 2025-10-16 N/A 9.8 CRITICAL
Azure Entra ID Elevation of Privilege Vulnerability
CVE-2025-55241 1 Microsoft 1 Entra Id 2025-09-24 N/A 10.0 CRITICAL
Azure Entra ID Elevation of Privilege Vulnerability
CVE-2024-43477 1 Microsoft 1 Entra Id 2025-01-29 N/A 7.5 HIGH
Improper access control in Decentralized Identity Services resulted in a vulnerability that allows an unauthenticated attacker to disable Verifiable ID's on another tenant.