entra vulnerabilities
CVEs whose affected-version data names the entra package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
4 CVEsRSS
CVE-2026-83711Critical· 10.0Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.
Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.
▾ MidnightMicrosoft · EntraEPSS 0.58%via NVD
CVE-2026-69851Critical· 9.9Microsoft Entra ID Elevation of Privilege Vulnerability
Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.
▾ MidnightMicrosoft · Microsoft EntraEPSS 0.43%via CVEORG
CVE-2026-69836Critical· 10.0PoCMicrosoft Entra ID Remote Code Execution Vulnerability
Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.
▾ AbyssalMicrosoft · Microsoft EntraEPSS 1.6%via CVEORG
CVE-2026-62869High· 8.8Azure Entra ID Spoofing Vulnerability
Insufficient verification of data authenticity in Azure Entra ID allows an authorized attacker to perform spoofing over a network.
▾ TwilightMicrosoft · Microsoft EntraEPSS 0.82%via CVEORG