azure_active_directory vulnerabilities
CVEs whose affected-version data names the azure_active_directory package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2026-50481Critical· 9.9Azure Active Directory Elevation of Privilege Vulnerability
Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.
▾ MidnightMicrosoft · Azure Active DirectoryEPSS 0.56%via CVEORG
CVE-2026-50653High· 7.5Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network.
Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network.
▾ TwilightMicrosoft · Azure Active DirectoryEPSS 1.2%via NVD
CVE-2026-50652High· 7.5Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network.
Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network.
▾ TwilightMicrosoft · Azure Active DirectoryEPSS 1.7%via NVD