CVE-2026-42901: Microsoft Entra ID Elevation of Privilege Vulnerability
Published May 21, 2026
·Updated
Microsoft Entra ID Elevation of Privilege Vulnerability
Other sources
Origin validation error in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.
— Microsoft
Affected Software
2 affected components
Microsoft Entra ID
Microsoft Entra ID
Event History
May 21, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·02:00 PM
Description
May 22, 2026
CVE Published
via MITRE·10:04 PM
Data Sourced
via MITRE·10:04 PM
DescriptionSeverity
Data Sourced
via NVD·11:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-42901?
CVE-2026-42901 has a severity rating of critical with a score of 10.
2
What does CVE-2026-42901 affect?
CVE-2026-42901 affects Microsoft Entra ID software and allows elevation of privilege due to an origin validation error.
3
How can I mitigate CVE-2026-42901?
To mitigate CVE-2026-42901, ensure that you apply the latest security updates provided by Microsoft for Entra ID.
4
Who can exploit CVE-2026-42901?
CVE-2026-42901 can be exploited by an unauthorized attacker over a network.
5
What are the potential impacts of CVE-2026-42901?
The impacts of CVE-2026-42901 include unauthorized privilege escalation, potentially allowing attackers to gain critical access to the system.