CVE-2026-62916: Microsoft Entra ID Elevation of Privilege Vulnerability
Published Sep 3, 2026
·Updated
Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.
Other sources
Microsoft Entra ID Elevation of Privilege Vulnerability
— Microsoft
Affected Software
2 affected components
Microsoft Microsoft Entra ID
Microsoft Entra ID
Event History
Sep 3, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·02:00 PM
Description
CVE Published
via MITRE·10:59 PM
Data Sourced
via MITRE·10:59 PM
DescriptionSeverity
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The vulnerability is rated as network-accessible with low attack complexity and requires no privileges or user interaction. An unauthorized attacker may be able to exploit it remotely.
2
What is the potential impact if exploitation succeeds?
Successful exploitation allows elevation of privileges in Microsoft Entra ID. The supplied severity vector indicates high confidentiality and integrity impact, with no availability impact indicated.
3
Is there evidence that this vulnerability is being exploited?
The supplied data marks exploit code maturity as unproven (E:U). It does not provide evidence of active exploitation.