CVE-2026-62869: Azure Entra ID Spoofing Vulnerability
Published Aug 6, 2026
·Updated
Azure Entra ID Spoofing Vulnerability
Other sources
Insufficient verification of data authenticity in Azure Entra ID allows an authorized attacker to perform spoofing over a network.
— Microsoft
Affected Software
2 affected components
Microsoft Entra ID
Microsoft Entra ID
Event History
Aug 6, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·02:00 PM
Affected Software
Updated
via Microsoft·02:00 PM
Description
Aug 11, 2026
CVE Published
via MITRE·05:07 PM
Data Sourced
via MITRE·05:07 PM
DescriptionSeverity
Data Sourced
via NVD·05:18 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-62869?
The severity of CVE-2026-62869 is classified as high with a score of 8.8.
2
What type of vulnerability is CVE-2026-62869?
CVE-2026-62869 is a spoofing vulnerability in Azure Entra ID caused by insufficient verification of data authenticity.
3
How do I fix CVE-2026-62869?
To mitigate CVE-2026-62869, ensure that you apply the latest security updates provided by Microsoft for Azure Entra ID.
4
Who is affected by CVE-2026-62869?
Users of Microsoft Entra ID are affected by CVE-2026-62869 as it allows an authorized attacker to perform spoofing over a network.
5
When was CVE-2026-62869 published?
CVE-2026-62869 was published on August 6, 2026.