Description
Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.
Published: 2026-07-02
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a server‑side request forgery (SSRF) in Microsoft Entra Provisioning Service (SyncFabric). An attacker who has authorized access can make the service send arbitrary HTTP requests to internal network resources, thereby elevating their privileges beyond the permissions of the authenticated account. This flaw is identified as CWE‑918.

Affected Systems

Microsoft Entra Provisioning Service (SyncFabric) is the only product affected. No specific version or patch level is disclosed, so every current deployment might be vulnerable until the issue is resolved.

Risk and Exploitability

The CVSS score of 9.9 marks it as critical; the EPSS score is below 1%, suggesting a low probability of exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. The flaw requires only an account with service access and allows the service to send arbitrary, which could expose protected resources. This is inferred from the SSRF description, but the CVE does not specify the extent of further compromise or detail how internal resources might be exploited.

Generated by OpenCVE AI on July 21, 2026 at 10:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Microsoft Entra Provisioning Service update as outlined in the Microsoft Security Response Center.
  • Configure the service to allow outbound network requests only to a whitelist of trusted destinations, limiting SSRF reach.
  • Enforce multi‑factor authentication for all users with access to the Provisioning Service to reduce the risk of credential compromise.
  • Implement network segmentation to isolate critical internal resources from potential SSRF‑enabled requests.

Generated by OpenCVE AI on July 21, 2026 at 10:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft microsoft Entra Provisioning Service
Vendors & Products Microsoft microsoft Entra Provisioning Service

Mon, 06 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Description Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.
Title Microsoft Entra Provisioning Service Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft entra Provisioning Service
Weaknesses CWE-918
CPEs cpe:2.3:a:microsoft:entra_provisioning_service:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft entra Provisioning Service
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Entra Provisioning Service Microsoft Entra Provisioning Service
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-22T20:29:07.157Z

Reserved: 2026-06-23T18:29:51.054Z

Link: CVE-2026-57100

cve-icon Vulnrichment

Updated: 2026-07-06T11:52:11.488Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T10:45:02Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)