Interoperability Suite Vulnerability in Himmelblau for Microsoft Azure Entra ID and Intune
CVE-2026-31957

10CRITICAL

Key Information:

Vendor
CVE Published:
11 March 2026

What is CVE-2026-31957?

The Himmelblau interoperability suite for Microsoft Azure Entra ID and Intune has a configuration issue that can lead to unauthenticated access. When deployed without a properly configured tenant domain in the himmelblau.conf file, it allows for authentication attempts from any Entra ID domain. This behavior was originally intended for local bootstrap scenarios but poses significant security risks in remote authentication environments. Users are advised to upgrade to version 3.1.0 or later to mitigate these risks.

Affected Version(s)

himmelblau >= 3.0.0, < 3.1.0

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.