PT-2026-42849 · Microsoft · Entra Id

Sridhar Periyasamy

+1

·

Published

2026-05-21

·

Updated

2026-05-27

·

CVE-2026-42901

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Microsoft Entra ID (affected versions not specified)
Description An origin validation error in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Origin Validation Error

Weakness Enumeration

Related Identifiers

BDU:2026-07699
CVE-2026-42901

Affected Products

Entra Id