Description
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Entra ID allows an authorized attacker to perform spoofing over a network.
Published: 2026-06-19
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an improper neutralization of input during web page generation in Microsoft Entra ID, classified as a cross‑site scripting (CWE‑79) flaw. An authorized attacker—an authenticated Entra ID user with permission to influence rendered content—can inject malicious script that runs in Microsoft Edge (Chromium‑based). When executed, the script can create a spoofed user interface over a network, enabling phishing or other spoofing attacks that may lead to credential compromise or unintended authorization.

Affected Systems

Microsoft Edge (Chromium‑based) users who view pages generated by Microsoft Entra ID are impacted. The advisory does not list a specific Edge version range; therefore, any Edge release that renders Entra ID content could be affected. The vulnerability is tied to the Entra ID integration, not to Edge itself.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity, reflecting significant impact on confidentiality, integrity, and availability for users who trust the rendered pages. The EPSS score of < 1% suggests a very low exploitation probability, but the flaw is not catalogued in the CISA KEV list. Exploitation requires an authenticated Entra ID account with permission to influence content. An attacker would embed a malicious script that, when rendered by the victim’s Edge browser, performs spoofing or phishing activities, potentially leading to credential compromise or further lateral movement.

Generated by OpenCVE AI on August 2, 2026 at 01:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Microsoft Edge update that includes the fix for CVE‑2026‑32208.
  • Restrict Entra ID custom content submission to only those accounts that require it, thereby limiting the attack surface for authenticated users.
  • Enable or reinforce browser‑level XSS protection, such as Content Security Policy, to prevent injected scripts from executing.

Generated by OpenCVE AI on August 2, 2026 at 01:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 01 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an authorized attacker to perform spoofing over a network. Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Entra ID allows an authorized attacker to perform spoofing over a network.
Title Microsoft Edge (Chromium-based) Spoofing Vulnerability Microsoft Entra ID Spoofing Vulnerability

Mon, 22 Jun 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 19 Jun 2026 21:15:00 +0000

Type Values Removed Values Added
Description Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an authorized attacker to perform spoofing over a network.
Title Microsoft Edge (Chromium-based) Spoofing Vulnerability
First Time appeared Microsoft
Microsoft edge Chromium
Weaknesses CWE-79
CPEs cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft edge Chromium
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Edge Chromium
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-28T22:18:21.963Z

Reserved: 2026-03-11T01:49:58.659Z

Link: CVE-2026-32208

cve-icon Vulnrichment

Updated: 2026-06-22T17:30:25.416Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T01:45:06Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')