Description
Insufficient verification of data authenticity in Azure Entra ID allows an authorized attacker to perform spoofing over a network.
Published: 2026-08-11
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Azure Entra ID contains a data validation weakness (CWE-345) where data authenticity is not fully verified, allowing an authorized attacker to forge identity information over a network. This can lead to impersonation of legitimate users, unauthorized access, and potential escalation of privileges. The vulnerability directly affects the confidentiality and integrity of authentication processes.

Affected Systems

The affected product is Microsoft Azure Entra ID, provided by Microsoft Entra. No specific version information is supplied, so all instances of Azure Entra ID deployed by an organization should be treated as potentially vulnerable until a patch is applied.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity, and the EPSS score is not available, so the current likelihood of exploitation cannot be quantified. The vulnerability is not listed in the CISA KEV catalog, suggesting it is not in widespread use yet. Based on the description, the likely attack vector is a network‑based spoofing attempt from an authenticated attacker, meaning the risk is higher for organizations with privileged or internal users.

Generated by OpenCVE AI on August 12, 2026 at 12:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Ensure Azure Entra ID token validation policies are enabled so that all identity tokens are strictly verified and any discrepancies are rejected
  • Apply the official Microsoft patch for CVE-2026-62869 as soon as it is released
  • Monitor authentication logs for abnormal or spoofed identity attempts and investigate any anomalies promptly
  • If possible, restrict privileged identity usage or temporarily disable vulnerable authentication flows until the patch is applied

Generated by OpenCVE AI on August 12, 2026 at 12:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:microsoft:entra_id:-:*:*:*:*:*:*:*

Wed, 12 Aug 2026 07:00:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft entra Id
Vendors & Products Microsoft entra Id

Tue, 11 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description Insufficient verification of data authenticity in Azure Entra ID allows an authorized attacker to perform spoofing over a network.
Title Azure Entra ID Spoofing Vulnerability
First Time appeared Microsoft
Microsoft microsoft Entra Id
Weaknesses CWE-345
CPEs cpe:2.3:a:microsoft:microsoft_entra_id:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft microsoft Entra Id
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Entra Id Microsoft Entra Id
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-31T20:08:14.313Z

Reserved: 2026-07-14T21:13:55.099Z

Link: CVE-2026-62869

cve-icon Vulnrichment

Updated: 2026-08-11T17:46:30.366Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T17:18:37.720

Modified: 2026-08-13T12:20:48.650

Link: CVE-2026-62869

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T12:30:03Z

Weaknesses
  • CWE-345

    Insufficient Verification of Data Authenticity