CVE-2026-40379: Azure Entra ID Spoofing Vulnerability
Azure Entra ID Spoofing Vulnerability
Other sources
Exposure of sensitive information to an unauthorized actor in Azure Entra ID allows an unauthorized attacker to perform spoofing over a network.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-40379?
CVE-2026-40379 has been classified as a critical vulnerability due to its potential to allow unauthorized spoofing attacks.
How do I fix CVE-2026-40379?
To fix CVE-2026-40379, ensure that the latest security updates and patches for Microsoft Enterprise Security Token Service (ESTS) are applied.
What impact does CVE-2026-40379 have on network security?
CVE-2026-40379 can lead to unauthorized access and potential data breaches by allowing attackers to exploit security tokens.
Who is affected by CVE-2026-40379?
Organizations using Microsoft Enterprise Security Token Service (ESTS) are affected by CVE-2026-40379.
What are the symptoms of CVE-2026-40379 exploitation?
Symptoms of exploitation may include unauthorized access attempts and unusual authentication patterns within network systems.