CVE-2026-84003: Microsoft Authentication Library (MSAL) for Node.js Spoofing Vulnerability
Authentication bypass by capture-replay in Microsoft Authentication Library (MSAL) for Node.js allows an unauthorized attacker to perform spoofing over a network.
Other sources
Microsoft Authentication Library (MSAL) for Node.js Spoofing Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 5.6.0
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The issue is exploitable over a network without privileges or user interaction, but the stated attack complexity is high. The vulnerability involves capture-replay leading to an authentication bypass and spoofing.
What security impact can exploitation have?
Successful exploitation can result in high confidentiality and integrity impact. No availability impact is indicated in the supplied severity vector.
Is there evidence that this vulnerability is being exploited in the wild?
The supplied exploit-code maturity rating is E:U, indicating exploit status is unknown. The report does not provide evidence of active exploitation.