Description
Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.
Published: 2026-08-06
Score: 9.9 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw resides in Microsoft Azure Active Directory. An attacker who already has authorized access can modify an identifier that is supposed to be immutable, called "maid". By tampering with this data the attacker can acquire higher privileges than originally granted, as the weakness involves modification of assumed‑immutable data (CWE‑471).

Affected Systems

Microsoft Azure Active Directory is the affected product. The vulnerability applies to any deployment of this identity management service that has not yet been patched for the reported flaw.

Risk and Exploitability

The CVSS score of 9.9 indicates critical severity. The EPSS score is not available, and the vulnerability is not yet listed in CISA KEV, but that does not reduce the risk. Exploitation requires a valid authenticated session; once an attacker can modify the "maid" value they can elevate privileges across the network. Given the widespread use of Azure AD, the potential impact is substantial and administrators should treat this as a high‑risk issue while monitoring for suspicious activity.

Generated by OpenCVE AI on August 7, 2026 at 01:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Azure Active Directory update as detailed in the Microsoft Security Response Center update guide.
  • Restrict privileged roles that can modify the "maid" field and enforce least‑privilege rules for Azure AD account management.
  • Enable detailed auditing of identity attribute changes and monitor logs for unexpected modifications to detect possible exploitation.

Generated by OpenCVE AI on August 7, 2026 at 01:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 01:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 07 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Description Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.
Title Azure Active Directory Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft azure Active Directory
Weaknesses CWE-471
CPEs cpe:2.3:a:microsoft:azure_active_directory:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft azure Active Directory
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Azure Active Directory
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-07T00:58:12.487Z

Reserved: 2026-06-04T18:59:53.336Z

Link: CVE-2026-50481

cve-icon Vulnrichment

Updated: 2026-08-07T00:58:07.500Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T01:30:03Z

Weaknesses
  • CWE-471

    Modification of Assumed-Immutable Data (MAID)