Description
Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over a network.
Published: 2026-06-19
Score: 10 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges across the network. The vulnerability arises from a flaw in the authentication process, enabling the attacker to gain higher-level access that would normally require legitimate credentials. This could lead to unauthorized creation or modification of resources, escalation of access rights, and potential compromise of the entire Azure AD tenant infrastructure.

Affected Systems

The affected systems are Microsoft Azure Active Directory services. All versions of Azure Active Directory are potentially vulnerable unless otherwise mitigated by a patch or update. No specific version details are provided by the CNA, so the entire Azure AD product family should be considered at risk.

Risk and Exploitability

The CVSS score of 10 indicates critical severity, implying that exploitation can lead to complete compromise of authentication controls. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, suggesting that while there is no current public exploitation data, the high CVSS warrants immediate concern. The most likely attack vector is over the network, where an unauthenticated or low-privileged attacker can exploit the authentication flaw to elevate privileges.

Generated by OpenCVE AI on June 19, 2026 at 22:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Azure Active Directory security update released by Microsoft to address the authentication flaw.
  • Enable multi‑factor authentication for all privileged accounts to add an additional credential barrier.
  • Enforce role‑based access control and regularly review privileged role assignments to minimize the attack surface.

Generated by OpenCVE AI on June 19, 2026 at 22:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 19 Jun 2026 21:15:00 +0000

Type Values Removed Values Added
Description Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over a network.
Title Azure Active Directory Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft azure Active Directory
Weaknesses CWE-287
CPEs cpe:2.3:a:microsoft:azure_active_directory:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft azure Active Directory
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Azure Active Directory
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-06-19T20:27:46.192Z

Reserved: 2026-05-12T16:07:22.616Z

Link: CVE-2026-45480

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-19T23:15:05Z

Weaknesses