Interoperability Suite Vulnerability in Himmelblau for Microsoft Azure Entra ID and Intune
CVE-2026-31957
10CRITICAL
What is CVE-2026-31957?
The Himmelblau interoperability suite for Microsoft Azure Entra ID and Intune has a configuration issue that can lead to unauthenticated access. When deployed without a properly configured tenant domain in the himmelblau.conf file, it allows for authentication attempts from any Entra ID domain. This behavior was originally intended for local bootstrap scenarios but poses significant security risks in remote authentication environments. Users are advised to upgrade to version 3.1.0 or later to mitigate these risks.
Affected Version(s)
himmelblau >= 3.0.0, < 3.1.0
