Server-Side Request Forgery in Microsoft Azure Active Directory
CVE-2026-69851

9.9CRITICAL

Key Information:

Vendor

Microsoft

Vendor
CVE Published:
20 August 2026

What is CVE-2026-69851?

An SSRF vulnerability exists in Microsoft Azure Active Directory, enabling an authorized attacker to manipulate requests sent from the server to internal infrastructure. This flaw can potentially lead to unauthorized privilege escalation within the network, impacting the confidentiality and integrity of data handled by the compromised service.

Affected Version(s)

Microsoft Entra -

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.