CVE-2026-35431: Microsoft Entra ID Entitlement Management Spoofing Vulnerability
Published Apr 23, 2026
·Updated
Microsoft Entra ID Entitlement Management Spoofing Vulnerability
Other sources
Server-side request forgery (ssrf) in Microsoft Entra ID Entitlement Management allows an unauthorized attacker to perform spoofing over a network.
— Microsoft
Affected Software
2 affected components
Microsoft Entra ID
Microsoft Entra ID
Event History
Apr 23, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·02:00 PM
Affected Software
Updated
via Microsoft·02:00 PM
Description
CVE Published
via MITRE·09:37 PM
Data Sourced
via MITRE·09:37 PM
DescriptionSeverity
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-35431?
CVE-2026-35431 has been rated as a critical vulnerability due to its potential for unauthorized access and spoofing.
2
How do I fix CVE-2026-35431?
To mitigate CVE-2026-35431, apply the latest security updates provided by Microsoft for Entra ID.
3
What type of vulnerability is CVE-2026-35431?
CVE-2026-35431 is classified as a spoofing vulnerability caused by server-side request forgery.
4
Who is affected by CVE-2026-35431?
Organizations using Microsoft Entra ID Entitlement Management are vulnerable to CVE-2026-35431.
5
What are the impacts of CVE-2026-35431?
CVE-2026-35431 can allow unauthorized attackers to perform spoofing activities over the network.