CVE-2026-59115: Microsoft Entra Provisioning Service Elevation of Privilege Vulnerability
Published Aug 6, 2026
·Updated
'.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.
Other sources
Microsoft Entra Provisioning Service Elevation of Privilege Vulnerability
— Microsoft
Affected Software
1 affected component
Microsoft Entra Provisioning Service
Event History
Aug 6, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·02:00 PM
Affected Software
Updated
via Microsoft·02:00 PM
Description
CVE Published
via MITRE·10:37 PM
Data Sourced
via MITRE·10:37 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2026-59115?
CVE-2026-59115 has a critical severity rating of 9.9.
2
How do I fix CVE-2026-59115?
To fix CVE-2026-59115, update Microsoft Entra Provisioning Service to the latest version provided by Microsoft.
3
What type of vulnerability is CVE-2026-59115?
CVE-2026-59115 is an Elevation of Privilege vulnerability.
4
What kind of impact can CVE-2026-59115 have on my network?
CVE-2026-59115 allows an authorized attacker to elevate privileges over a network, potentially compromising sensitive data.
5
Is CVE-2026-59115 exploitable remotely?
Yes, CVE-2026-59115 is exploitable remotely.