entra_id vulnerabilities
CVEs whose affected-version data names the entra_id package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2026-83941Critical· 9.9Missing authorization in Entra ID allows an authorized attacker to elevate privileges over a network.
Missing authorization in Entra ID allows an authorized attacker to elevate privileges over a network.
▾ Midnightmicrosoft · entra_idEPSS 0.78%via NVD
CVE-2026-62916Critical· 9.1Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.
Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.
▾ Midnightmicrosoft · entra_idEPSS 0.60%via NVD
CVE-2026-33843Critical· 9.1Authentication bypass using an alternate path or channel in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.
Authentication bypass using an alternate path or channel in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.
▾ Midnightmicrosoft · entra_idEPSS 0.47%via NVD