ZDI-CAN-30176: ZDI-26-629: Microsoft Azure Entra ID OAuth Device Code Grant Information Disclosure Vulnerability
Published Sep 9, 2026
·Updated
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Microsoft Azure. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.8.
Affected Software
1 affected component
Microsoft Azure Entra ID
Event History
Sep 9, 2026
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
Does exploitation require an authenticated Azure Entra ID account?
No. The advisory states that authentication is not required, so a remote unauthenticated attacker can exploit the issue.
2
What is the reported impact and severity?
The reported impact is disclosure of sensitive information. ZDI assigned the vulnerability a CVSS score of 5.8.