CVE-2026-24305: Azure Entra ID Elevation of Privilege Vulnerability
Published Jan 22, 2026
·Updated
Azure Entra ID Elevation of Privilege Vulnerability
Affected Software
2 affected components
Microsoft Entra ID
Microsoft Entra ID
Event History
Jan 22, 2026
CVE Published
via Microsoft·08:00 AM
Data Sourced
via Microsoft·08:00 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·04:00 PM
Description
CVE Published
via MITRE·10:47 PM
Data Sourced
via MITRE·10:47 PM
DescriptionSeverity
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeaknessAffected Software
Feb 27, 58104
Event
via FIRST·01:50 PM
Frequently Asked Questions
1
What is the severity of CVE-2026-24305?
CVE-2026-24305 is classified as an elevation of privilege vulnerability.
2
How do I fix CVE-2026-24305?
To address CVE-2026-24305, apply the latest security updates and patches from Microsoft for Azure Entra ID.
3
What can happen if CVE-2026-24305 is exploited?
Exploiting CVE-2026-24305 could allow an attacker to gain elevated privileges within the Azure Entra ID environment.
4
Which software is affected by CVE-2026-24305?
CVE-2026-24305 specifically affects Microsoft Entra ID.
5
Is there a workaround for CVE-2026-24305?
Currently, the recommended approach is to apply the security updates rather than relying on workarounds for CVE-2026-24305.