Elevation of Privilege Vulnerability in Microsoft Entra ID
CVE-2026-42901

10CRITICAL

Key Information:

Vendor

Microsoft

Vendor
CVE Published:
22 May 2026

What is CVE-2026-42901?

An origin validation error in Microsoft Entra ID permits unauthorized attackers to elevate their privileges within a network environment. This flaw could allow for malicious activities, enabling access to sensitive functions and data. Organizations utilizing Microsoft Entra ID should take immediate action to apply available security updates and patches to mitigate this vulnerability.

Affected Version(s)

Microsoft Entra -

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.