Elevation of Privilege Vulnerability in Microsoft Entra Provisioning Service
CVE-2026-59115

9.9CRITICAL

Key Information:

Vendor

Microsoft

Vendor
CVE Published:
6 August 2026

What is CVE-2026-59115?

An elevation of privilege vulnerability in Microsoft Entra Provisioning Service (SyncFabric) may allow an authorized attacker to gain enhanced privileges over a networked environment. This flaw could enable the attacker to perform unauthorized actions, thus impacting the integrity and confidentiality of the system. Vigilance and timely patching are crucial to mitigate potential risks associated with this security issue.

Affected Version(s)

Microsoft Entra Provisioning Service -

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.