CVE-2026-69851: Microsoft Entra ID Elevation of Privilege Vulnerability
Published Aug 20, 2026
·Updated
Microsoft Entra ID Elevation of Privilege Vulnerability
Other sources
Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.
— Microsoft
Affected Software
2 affected components
Microsoft Microsoft Entra ID
Microsoft Entra ID
Event History
Aug 20, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·02:00 PM
Description
CVE Published
via MITRE·09:43 PM
Data Sourced
via MITRE·09:43 PM
DescriptionSeverity
Frequently Asked Questions
1
What access must an attacker have before attempting exploitation?
The attacker must already be authorized. The vulnerability does not describe exploitation by an unauthenticated attacker.
2
Does exploitation require user interaction or local access?
No user interaction is required, and the attack vector is network-based. An authorized attacker can exploit it over a network.